Stack-based buffer overflow in the krb5_klog_syslog function in the kadm5 library, as used by the Kerberos administration daemon (kadmind) and Key Distribution Center (KDC), in MIT krb5 before 1.6.1 allows remote authenticated users to execute arbitrary code and modify the Kerberos key database via crafted arguments, possibly involving certain format string specifiers.
CVSS Details
- CVSS 3.1 Base Score: 8.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apple Osx Kerberos | — | Apply OS X security update 2007-004 | Dec 16, 2011 | Apr 5, 2007 |
| Debian | — | Upgrade krb5 | Jul 30, 2024 | Apr 6, 2007 |
| Gentoo Linux | — | Upgrade app-crypt/mit-krb5. | Oct 30, 2017 | Apr 5, 2007 |
| Oracle_linux | — | Upgrade krb5-workstationUpgrade krb5-develUpgrade krb5-serverUpgrade krb5-libs | Oct 16, 2024 | Apr 6, 2007 |
| Suse | — | Upgrade krb5-apps-serversUpgrade krb5-32bitUpgrade krb5-apps-clientsUpgrade krb5Upgrade krb5-devel-32bitUpgrade krb5-x86Upgrade krb5-develUpgrade krb5-serverUpgrade krb5-plugin-preauth-otpUpgrade krb5-plugin-preauth-pkinitUpgrade krb5-plugin-kdb-ldapUpgrade krb5-plugin-preauth-spakeUpgrade krb5-client | Feb 17, 2015 | Jun 28, 2013 |
| Ubuntu | — | Upgrade krb5-telnetdUpgrade libkadm55Upgrade libkrb53 | Nov 8, 2024 | Apr 6, 2007 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub