Back

HIGH

krb5: ftpd - use of uninitialized variables

Published Dec 6, 2007

Description

The reply function in ftpd.c in the gssftp ftpd in MIT Kerberos 5 (krb5) does not initialize the length variable when auth_type has a certain value, which has unknown impact and remote authenticated attack vectors. NOTE: the original disclosure misidentifies the conditions under which the uninitialized variable is used. NOTE: the vendor disputes this issue, stating " The 'length' variable is only uninitialized if 'auth_type' is neither the 'KERBEROS_V4' nor 'GSSAPI'; this condition cannot occur in the unmodified source code.

Affected products

Remediation

Red Hat statement

This issue is not a vulnerability, for more information see https://marc.info/?m=119743235325151

Metrics

Weaknesses (0)

No CWE recorded.

References (16)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Dec 6, 2007
Updated Aug 7, 2024
Reserved Nov 8, 2007
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Low
Public date Nov 14, 2007