Stack-based buffer overflow in the krb5_klog_syslog function in the kadm5 library, as used by the Kerberos administration daemon (kadmind) and Key Distribution Center (KDC), in MIT krb5 before 1.6.1 allows remote authenticated users to execute arbitrary code and modify the Kerberos key database via crafted arguments, possibly involving certain format string specifiers.
Metrics
Affected Vendors & Products
Advisories
Source | ID | Title |
---|---|---|
![]() |
DSA-1276-1 | New krb5 packages fix several vulnerabilities |
![]() |
USN-449-1 | krb5 vulnerabilities |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.

Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-07T12:34:21.284Z
Reserved: 2007-02-14T00:00:00
Link: CVE-2007-0957

No data.

Status : Deferred
Published: 2007-04-06T01:19:00.000
Modified: 2025-04-09T00:30:58.490
Link: CVE-2007-0957


No data.