The reply function in ftpd.c in the gssftp ftpd in MIT Kerberos 5 (krb5) does not initialize the length variable when auth_type has a certain value, which has unknown impact and remote authenticated attack vectors. NOTE: the original disclosure misidentifies the conditions under which the uninitialized variable is used. NOTE: the vendor disputes this issue, stating " The 'length' variable is only uninitialized if 'auth_type' is neither the 'KERBEROS_V4' nor 'GSSAPI'; this condition cannot occur in the unmodified source code.
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade krb5 | Jul 30, 2024 | Dec 6, 2007 |
| Suse | — | Upgrade krb5Upgrade krb5-plugin-preauth-pkinitUpgrade krb5-plugin-preauth-otpUpgrade krb5-apps-clientsUpgrade krb5-32bitUpgrade krb5-plugin-preauth-spakeUpgrade krb5-apps-serversUpgrade krb5-clientUpgrade krb5-x86Upgrade krb5-devel-32bitUpgrade krb5-develUpgrade krb5-plugin-kdb-ldapUpgrade krb5-server | Feb 17, 2015 | Jul 9, 2013 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub