krb5: double free in gssapi lib
Published Dec 6, 2007
6.9
MEDIUMCVSS 2.0
EPSS 0.37%
Description
Double free vulnerability in the gss_krb5int_make_seal_token_v3 function in lib/gssapi/krb5/k5sealv3.c in MIT Kerberos 5 (krb5) has unknown impact and attack vectors.
Affected products
No data.
Running on/with
- 10.4.11
- 10.5.2
- 10.4.11
- 10.5.2
- ≤ 1.6.3_kdc
No data.
Red Hat Enterprise Linux 4
krb5-0:1.3.4-54.el4_6.1
Fixed · RHSA-2008:0180
Red Hat Enterprise Linux 5
krb5-0:1.6.1-17.el5_1.1
Fixed · RHSA-2008:0164
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 4 | krb5-0:1.3.4-54.el4_6.1 | Fixed | RHSA-2008:0180 |
| Red Hat Enterprise Linux 5 | krb5-0:1.6.1-17.el5_1.1 | Fixed | RHSA-2008:0164 |
No package ranges for this CVE.
Remediation
Red Hat statement
Red Hat is aware of this issue and is tracking it via the following bug: https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=CVE-2007-5971 The Red Hat Product Security has rated this issue as having low security impact, a future update may address this flaw. See https://marc.info/?m=119743235325151
References (39)
- http://bugs.gentoo.org/show_bug.cgi?id=199212 x_refsource_MISC
- http://docs.info.apple.com/article.html?artnum=307562 x_refsource_CONFIRM
- http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html vendor-advisoryx_refsource_APPLE
- http://osvdb.org/43345 vdb-entryx_refsource_OSVDB
- http://seclists.org/fulldisclosure/2007/Dec/0176.html mailing-listx_refsource_FULLDISC
- http://seclists.org/fulldisclosure/2007/Dec/0321.html mailing-listx_refsource_FULLDISC
- http://secunia.com/advisories/28636 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/29420 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/29450 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/29451 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/29457 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/29462 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/29464 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/29516 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/39290 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/39784 third-party-advisoryx_refsource_SECUNIA
- http://security.gentoo.org/glsa/glsa-200803-31.xml vendor-advisoryx_refsource_GENTOO
- http://ubuntu.com/usn/usn-924-1 vendor-advisoryx_refsource_UBUNTU
- http://wiki.rpath.com/Advisories:rPSA-2008-0112 x_refsource_CONFIRM
- http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0112 x_refsource_CONFIRM
- http://www.mandriva.com/security/advisories?name=MDVSA-2008:069 vendor-advisoryx_refsource_MANDRIVA
- http://www.mandriva.com/security/advisories?name=MDVSA-2008:070 vendor-advisoryx_refsource_MANDRIVA
- http://www.novell.com/linux/security/advisories/suse_security_summary_report.html vendor-advisoryx_refsource_SUSE
- http://www.redhat.com/support/errata/RHSA-2008-0164.html vendor-advisoryx_refsource_REDHAT
- http://www.redhat.com/support/errata/RHSA-2008-0180.html vendor-advisoryx_refsource_REDHAT
- http://www.securityfocus.com/archive/1/489883/100/0/threaded mailing-listx_refsource_BUGTRAQ
- http://www.securityfocus.com/bid/26750 vdb-entryx_refsource_BIDPatch
- http://www.ubuntu.com/usn/USN-940-1 vendor-advisoryx_refsource_UBUNTU
- http://www.vupen.com/english/advisories/2008/0924/references vdb-entryx_refsource_VUPEN
- http://www.vupen.com/english/advisories/2010/1192 vdb-entryx_refsource_VUPEN
- https://access.redhat.com/security/cve/CVE-2007-5971 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=415351 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2007-5941 Advisory
- https://issues.rpath.com/browse/RPL-2012 x_refsource_CONFIRM
- https://nvd.nist.gov/vuln/detail/CVE-2007-5971
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10296 vdb-entrysignaturex_refsource_OVAL
- https://www.cve.org/CVERecord?id=CVE-2007-5971
- https://www.redhat.com/archives/fedora-package-announce/2008-March/msg00537.html vendor-advisoryx_refsource_FEDORA
- https://www.redhat.com/archives/fedora-package-announce/2008-March/msg00544.html vendor-advisoryx_refsource_FEDORA
Change history (0)
No recorded changes yet.