Description
Double free vulnerability in the GSS-API library (lib/gssapi/krb5/k5unseal.c), as used by the Kerberos administration daemon (kadmind) in MIT krb5 before 1.6.1, when used with the authentication method provided by the RPCSEC_GSS RPC library, allows remote authenticated users to execute arbitrary code and modify the Kerberos key database via a message with an "an invalid direction encoding".
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-1276-1 | New krb5 packages fix several vulnerabilities |
Ubuntu USN |
USN-449-1 | krb5 vulnerabilities |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-07T12:50:34.980Z
Reserved: 2007-03-02T00:00:00.000Z
Link: CVE-2007-1216
No data.
Status : Modified
Published: 2007-04-06T01:19:00.000
Modified: 2026-04-23T00:35:47.467
Link: CVE-2007-1216
OpenCVE Enrichment
No data.
Weaknesses
Debian DSA
Ubuntu USN