Back

MEDIUM

krb5: use-after-free in gssapi lib

Published Dec 6, 2007

Description

Use-after-free vulnerability in the gss_indicate_mechs function in lib/gssapi/mechglue/g_initialize.c in MIT Kerberos 5 (krb5) has unknown impact and attack vectors. NOTE: this might be the result of a typo in the source code.

Affected products

Remediation

Red Hat statement

Red Hat is aware of this issue and is tracking it via the following bug: https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=CVE-2007-5901 The Red Hat Product Security has rated this issue as having low security impact, a future update may address this flaw.

Metrics

References (24)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Dec 6, 2007
Updated Aug 7, 2024
Reserved Nov 9, 2007
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Low
Public date Nov 14, 2007