Description
The gssrpc__svcauth_gssapi function in the RPC library in MIT Kerberos 5 (krb5) 1.6.1 and earlier might allow remote attackers to execute arbitrary code via a zero-length RPC credential, which causes kadmind to free an uninitialized pointer during cleanup.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-1323-1 | New krb5 packages fix several vulnerabilities |
Ubuntu USN |
USN-477-1 | krb5 vulnerabilities |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-07T13:42:32.340Z
Reserved: 2007-05-02T00:00:00.000Z
Link: CVE-2007-2442
No data.
Status : Modified
Published: 2007-06-26T22:30:00.000
Modified: 2026-04-23T00:35:47.467
Link: CVE-2007-2442
OpenCVE Enrichment
No data.
Weaknesses
Debian DSA
Ubuntu USN