Back

HIGH

krb5 RPC library buffer overflow

Published Sep 5, 2007

Description

Stack-based buffer overflow in the svcauth_gss_validate function in lib/rpc/svc_auth_gss.c in the RPCSEC_GSS RPC library (librpcsecgss) in MIT Kerberos 5 (krb5) 1.4 through 1.6.2, as used by the Kerberos administration daemon (kadmind) and some third-party applications that use krb5, allows remote attackers to cause a denial of service (daemon crash) and probably execute arbitrary code via a long string in an RPC message.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (65)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Sep 5, 2007
Updated Aug 7, 2024
Reserved Jul 25, 2007
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Important
Public date Sep 4, 2007