The "mechglue" abstraction interface of the GSS-API library for Kerberos 5 1.5 through 1.5.1, as used in Kerberos administration daemon (kadmind) and other products that use this library, allows remote attackers to cause a denial of service (crash) via unspecified vectors that cause mechglue to free uninitialized pointers
Published Jan 10, 2007
5.0
MEDIUMCVSS 2.0
EPSS 5.38%
Description
The "mechglue" abstraction interface of the GSS-API library for Kerberos 5 1.5 through 1.5.1, as used in Kerberos administration daemon (kadmind) and other products that use this library, allows remote attackers to cause a denial of service (crash) via unspecified vectors that cause mechglue to free uninitialized pointers.
Affected products
No data.
- ≥ 1.5 · ≤ 1.5.1
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Red Hat statement
Not vulnerable. Red Hat Enterprise Linux 2.1, 3, and 4 ship with versions of Kerberos 5 prior to version 1.4 and are therefore not affected by these vulnerabilities. Red Hat Enterprise Linux 5 is not vulnerable to this issue as it contains a backported patch.
No CWE recorded.
References (25)
- http://fedoranews.org/cms/node/2375 vendor-advisoryx_refsource_FEDORABroken Link
- http://lists.suse.com/archive/suse-security-announce/2007-Jan/0004.html vendor-advisoryx_refsource_SUSEBroken Link
- http://osvdb.org/31280 vdb-entryx_refsource_OSVDBBroken Link
- http://secunia.com/advisories/23690 third-party-advisoryx_refsource_SECUNIAThird Party Advisory
- http://secunia.com/advisories/23701 third-party-advisoryx_refsource_SECUNIAThird Party Advisory
- http://secunia.com/advisories/23706 third-party-advisoryx_refsource_SECUNIAThird Party Advisory
- http://secunia.com/advisories/23903 third-party-advisoryx_refsource_SECUNIAThird Party Advisory
- http://secunia.com/advisories/35151 third-party-advisoryx_refsource_SECUNIAThird Party Advisory
- http://security.gentoo.org/glsa/glsa-200701-21.xml vendor-advisoryx_refsource_GENTOOThird Party Advisory
- http://securitytracker.com/id?1017494 vdb-entryx_refsource_SECTRACKThird Party AdvisoryVDB Entry
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-102772-1 vendor-advisoryx_refsource_SUNALERTBroken Link
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-201294-1 vendor-advisoryx_refsource_SUNALERTBroken Link
- http://web.mit.edu/kerberos/www/advisories/MITKRB5-SA-2006-003-mechglue.txt x_refsource_CONFIRMPatchVendor Advisory
- http://www.kb.cert.org/vuls/id/831452 third-party-advisoryx_refsource_CERT-VNThird Party AdvisoryUS Government Resource
- http://www.openpkg.com/security/advisories/OpenPKG-SA-2007.006.html vendor-advisoryx_refsource_OPENPKGThird Party Advisory
- http://www.securityfocus.com/archive/1/456409/100/0/threaded mailing-listx_refsource_BUGTRAQThird Party AdvisoryVDB Entry
- http://www.securityfocus.com/bid/21975 vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry
- http://www.us-cert.gov/cas/techalerts/TA07-009B.html third-party-advisoryx_refsource_CERTThird Party AdvisoryUS Government Resource
- http://www.vupen.com/english/advisories/2007/0111 vdb-entryx_refsource_VUPENThird Party Advisory
- http://www.vupen.com/english/advisories/2007/0112 vdb-entryx_refsource_VUPENThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2006-6144 Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/31417 vdb-entryx_refsource_XFThird Party AdvisoryVDB Entry
- https://issues.rpath.com/browse/RPL-925 x_refsource_CONFIRMBroken Link
- https://nvd.nist.gov/vuln/detail/CVE-2006-6144
- https://www.cve.org/CVERecord?id=CVE-2006-6144
| Link | Providers | Tags |
|---|---|---|
| http://fedoranews.org/cms/node/2375 | vendor-advisoryx_refsource_FEDORABroken Link | |
| http://lists.suse.com/archive/suse-security-announce/2007-Jan/0004.html | vendor-advisoryx_refsource_SUSEBroken Link | |
| http://osvdb.org/31280 | vdb-entryx_refsource_OSVDBBroken Link | |
| http://secunia.com/advisories/23690 | third-party-advisoryx_refsource_SECUNIAThird Party Advisory | |
| http://secunia.com/advisories/23701 | third-party-advisoryx_refsource_SECUNIAThird Party Advisory | |
| http://secunia.com/advisories/23706 | third-party-advisoryx_refsource_SECUNIAThird Party Advisory | |
| http://secunia.com/advisories/23903 | third-party-advisoryx_refsource_SECUNIAThird Party Advisory | |
| http://secunia.com/advisories/35151 | third-party-advisoryx_refsource_SECUNIAThird Party Advisory | |
| http://security.gentoo.org/glsa/glsa-200701-21.xml | vendor-advisoryx_refsource_GENTOOThird Party Advisory | |
| http://securitytracker.com/id?1017494 | vdb-entryx_refsource_SECTRACKThird Party AdvisoryVDB Entry | |
| http://sunsolve.sun.com/search/document.do?assetkey=1-26-102772-1 | vendor-advisoryx_refsource_SUNALERTBroken Link | |
| http://sunsolve.sun.com/search/document.do?assetkey=1-26-201294-1 | vendor-advisoryx_refsource_SUNALERTBroken Link | |
| http://web.mit.edu/kerberos/www/advisories/MITKRB5-SA-2006-003-mechglue.txt | x_refsource_CONFIRMPatchVendor Advisory | |
| http://www.kb.cert.org/vuls/id/831452 | third-party-advisoryx_refsource_CERT-VNThird Party AdvisoryUS Government Resource | |
| http://www.openpkg.com/security/advisories/OpenPKG-SA-2007.006.html | vendor-advisoryx_refsource_OPENPKGThird Party Advisory | |
| http://www.securityfocus.com/archive/1/456409/100/0/threaded | mailing-listx_refsource_BUGTRAQThird Party AdvisoryVDB Entry | |
| http://www.securityfocus.com/bid/21975 | vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry | |
| http://www.us-cert.gov/cas/techalerts/TA07-009B.html | third-party-advisoryx_refsource_CERTThird Party AdvisoryUS Government Resource | |
| http://www.vupen.com/english/advisories/2007/0111 | vdb-entryx_refsource_VUPENThird Party Advisory | |
| http://www.vupen.com/english/advisories/2007/0112 | vdb-entryx_refsource_VUPENThird Party Advisory | |
| https://access.redhat.com/security/cve/CVE-2006-6144 | Vendor Advisory | |
| https://exchange.xforce.ibmcloud.com/vulnerabilities/31417 | vdb-entryx_refsource_XFThird Party AdvisoryVDB Entry | |
| https://issues.rpath.com/browse/RPL-925 | x_refsource_CONFIRMBroken Link | |
| https://nvd.nist.gov/vuln/detail/CVE-2006-6144 | ||
| https://www.cve.org/CVERecord?id=CVE-2006-6144 |
Change history (0)
No recorded changes yet.