The RPC library in Kerberos 5 1.4 through 1.4.4, and 1.5 through 1.5.1, as used in Kerberos administration daemon (kadmind) and other products that use this library, calls an uninitialized function pointer in freed memory, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unspecified vectors
Published Jan 10, 2007
9.3
HIGHCVSS 2.0
EPSS 7.92%
Description
The RPC library in Kerberos 5 1.4 through 1.4.4, and 1.5 through 1.5.1, as used in Kerberos administration daemon (kadmind) and other products that use this library, calls an uninitialized function pointer in freed memory, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unspecified vectors.
Affected products
No data.
Configuration 1
- 1.4
- 1.4.1
- 1.4.2
- 1.4.3
- 1.4.4
- 1.5
- 1.5.1
Configuration 2
- 6.06
- 6.10
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Red Hat statement
Not vulnerable. Red Hat Enterprise Linux 2.1, 3, and 4 ship with versions of Kerberos 5 prior to version 1.4 and are therefore not affected by these vulnerabilities. Red Hat Enterprise Linux 5 is not vulnerable to this issue as it contains a backported patch.
References (33)
- http://docs.info.apple.com/article.html?artnum=305391 x_refsource_CONFIRMBroken Link
- http://fedoranews.org/cms/node/2375 vendor-advisoryx_refsource_FEDORABroken Link
- http://fedoranews.org/cms/node/2376 vendor-advisoryx_refsource_FEDORABroken Link
- http://lists.apple.com/archives/Security-announce/2007/Apr/msg00001.html vendor-advisoryx_refsource_APPLEMailing List
- http://lists.suse.com/archive/suse-security-announce/2007-Jan/0004.html vendor-advisoryx_refsource_SUSEBroken Link
- http://osvdb.org/31281 vdb-entryx_refsource_OSVDBBroken Link
- http://secunia.com/advisories/23667 third-party-advisoryx_refsource_SECUNIABroken Link
- http://secunia.com/advisories/23696 third-party-advisoryx_refsource_SECUNIABroken Link
- http://secunia.com/advisories/23701 third-party-advisoryx_refsource_SECUNIABroken Link
- http://secunia.com/advisories/23706 third-party-advisoryx_refsource_SECUNIABroken Link
- http://secunia.com/advisories/23707 third-party-advisoryx_refsource_SECUNIABroken Link
- http://secunia.com/advisories/23772 third-party-advisoryx_refsource_SECUNIABroken Link
- http://secunia.com/advisories/23903 third-party-advisoryx_refsource_SECUNIABroken Link
- http://secunia.com/advisories/24966 third-party-advisoryx_refsource_SECUNIABroken Link
- http://security.gentoo.org/glsa/glsa-200701-21.xml vendor-advisoryx_refsource_GENTOOThird Party Advisory
- http://securitytracker.com/id?1017493 vdb-entryx_refsource_SECTRACKBroken LinkThird Party AdvisoryVDB Entry
- http://web.mit.edu/kerberos/www/advisories/MITKRB5-SA-2006-002-rpc.txt x_refsource_CONFIRMPatchVendor Advisory
- http://www.kb.cert.org/vuls/id/481564 third-party-advisoryx_refsource_CERT-VNPatchThird Party AdvisoryUS Government Resource
- http://www.mandriva.com/security/advisories?name=MDKSA-2007:008 vendor-advisoryx_refsource_MANDRIVAThird Party Advisory
- http://www.openpkg.com/security/advisories/OpenPKG-SA-2007.006.html vendor-advisoryx_refsource_OPENPKGBroken Link
- http://www.securityfocus.com/archive/1/456406/100/0/threaded mailing-listx_refsource_BUGTRAQBroken LinkThird Party AdvisoryVDB Entry
- http://www.securityfocus.com/bid/21970 vdb-entryx_refsource_BIDBroken LinkThird Party AdvisoryVDB Entry
- http://www.ubuntu.com/usn/usn-408-1 vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- http://www.us-cert.gov/cas/techalerts/TA07-009B.html third-party-advisoryx_refsource_CERTBroken LinkPatchThird Party AdvisoryUS Government Resource
- http://www.us-cert.gov/cas/techalerts/TA07-109A.html third-party-advisoryx_refsource_CERTBroken LinkThird Party AdvisoryUS Government Resource
- http://www.vupen.com/english/advisories/2007/0111 vdb-entryx_refsource_VUPENBroken Link
- http://www.vupen.com/english/advisories/2007/1470 vdb-entryx_refsource_VUPENBroken Link
- https://access.redhat.com/security/cve/CVE-2006-6143 Vendor Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2006-6126 Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/31422 vdb-entryx_refsource_XFThird Party AdvisoryVDB Entry
- https://issues.rpath.com/browse/RPL-925 x_refsource_CONFIRMBroken Link
- https://nvd.nist.gov/vuln/detail/CVE-2006-6143
- https://www.cve.org/CVERecord?id=CVE-2006-6143
| Link | Providers | Tags |
|---|---|---|
| http://docs.info.apple.com/article.html?artnum=305391 | x_refsource_CONFIRMBroken Link | |
| http://fedoranews.org/cms/node/2375 | vendor-advisoryx_refsource_FEDORABroken Link | |
| http://fedoranews.org/cms/node/2376 | vendor-advisoryx_refsource_FEDORABroken Link | |
| http://lists.apple.com/archives/Security-announce/2007/Apr/msg00001.html | vendor-advisoryx_refsource_APPLEMailing List | |
| http://lists.suse.com/archive/suse-security-announce/2007-Jan/0004.html | vendor-advisoryx_refsource_SUSEBroken Link | |
| http://osvdb.org/31281 | vdb-entryx_refsource_OSVDBBroken Link | |
| http://secunia.com/advisories/23667 | third-party-advisoryx_refsource_SECUNIABroken Link | |
| http://secunia.com/advisories/23696 | third-party-advisoryx_refsource_SECUNIABroken Link | |
| http://secunia.com/advisories/23701 | third-party-advisoryx_refsource_SECUNIABroken Link | |
| http://secunia.com/advisories/23706 | third-party-advisoryx_refsource_SECUNIABroken Link | |
| http://secunia.com/advisories/23707 | third-party-advisoryx_refsource_SECUNIABroken Link | |
| http://secunia.com/advisories/23772 | third-party-advisoryx_refsource_SECUNIABroken Link | |
| http://secunia.com/advisories/23903 | third-party-advisoryx_refsource_SECUNIABroken Link | |
| http://secunia.com/advisories/24966 | third-party-advisoryx_refsource_SECUNIABroken Link | |
| http://security.gentoo.org/glsa/glsa-200701-21.xml | vendor-advisoryx_refsource_GENTOOThird Party Advisory | |
| http://securitytracker.com/id?1017493 | vdb-entryx_refsource_SECTRACKBroken LinkThird Party AdvisoryVDB Entry | |
| http://web.mit.edu/kerberos/www/advisories/MITKRB5-SA-2006-002-rpc.txt | x_refsource_CONFIRMPatchVendor Advisory | |
| http://www.kb.cert.org/vuls/id/481564 | third-party-advisoryx_refsource_CERT-VNPatchThird Party AdvisoryUS Government Resource | |
| http://www.mandriva.com/security/advisories?name=MDKSA-2007:008 | vendor-advisoryx_refsource_MANDRIVAThird Party Advisory | |
| http://www.openpkg.com/security/advisories/OpenPKG-SA-2007.006.html | vendor-advisoryx_refsource_OPENPKGBroken Link | |
| http://www.securityfocus.com/archive/1/456406/100/0/threaded | mailing-listx_refsource_BUGTRAQBroken LinkThird Party AdvisoryVDB Entry | |
| http://www.securityfocus.com/bid/21970 | vdb-entryx_refsource_BIDBroken LinkThird Party AdvisoryVDB Entry | |
| http://www.ubuntu.com/usn/usn-408-1 | vendor-advisoryx_refsource_UBUNTUThird Party Advisory | |
| http://www.us-cert.gov/cas/techalerts/TA07-009B.html | third-party-advisoryx_refsource_CERTBroken LinkPatchThird Party AdvisoryUS Government Resource | |
| http://www.us-cert.gov/cas/techalerts/TA07-109A.html | third-party-advisoryx_refsource_CERTBroken LinkThird Party AdvisoryUS Government Resource | |
| http://www.vupen.com/english/advisories/2007/0111 | vdb-entryx_refsource_VUPENBroken Link | |
| http://www.vupen.com/english/advisories/2007/1470 | vdb-entryx_refsource_VUPENBroken Link | |
| https://access.redhat.com/security/cve/CVE-2006-6143 | Vendor Advisory | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2006-6126 | Advisory | |
| https://exchange.xforce.ibmcloud.com/vulnerabilities/31422 | vdb-entryx_refsource_XFThird Party AdvisoryVDB Entry | |
| https://issues.rpath.com/browse/RPL-925 | x_refsource_CONFIRMBroken Link | |
| https://nvd.nist.gov/vuln/detail/CVE-2006-6143 | ||
| https://www.cve.org/CVERecord?id=CVE-2006-6143 |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
No data
Red Hat
No data
GitHub
No data