CVE-2007-2798
HIGH severity · CVSS 9 · Out-of-bounds write
9CVSS HIGH
Summary
Stack-based buffer overflow in the rename_principal_2_svc function in kadmind for MIT Kerberos 1.5.3, 1.6.1, and other versions allows remote authenticated users to execute arbitrary code via a crafted request to rename a principal.
Impact & exploitability
Attack vectorNetwork
Attack complexityLow
Privileges required—
User interaction—
Confidentiality impact—
Integrity impact—
Availability impact—
Exploit probability (EPSS)8%
AV:N/AC:L/Au:S/C:C/I:C/A:C
Affected products we track (1)
Recommendation
Apply the vendor fix promptly. Open any affected product above for its exact safe version.
Additional information
- NVD record
- ftp://patches.sgi.com/support/free/security/advisories/20070602-01-P.asc
- http://docs.info.apple.com/article.html?artnum=306172
- http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c02257427
- http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=548
- http://lists.apple.com/archives/security-announce//2007/Jul/msg00004.htmlAdvisory
- http://lists.grok.org.uk/pipermail/full-disclosure/2007-September/065902.htmlAdvisory
- http://osvdb.org/36595
- http://secunia.com/advisories/25800Advisory