Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2007-1216

Опубликовано: 06 апр. 2007
Источник: ubuntu
Приоритет: medium
EPSS Средний
CVSS2: 9

Описание

Double free vulnerability in the GSS-API library (lib/gssapi/krb5/k5unseal.c), as used by the Kerberos administration daemon (kadmind) in MIT krb5 before 1.6.1, when used with the authentication method provided by the RPCSEC_GSS RPC library, allows remote authenticated users to execute arbitrary code and modify the Kerberos key database via a message with an "an invalid direction encoding".

РелизСтатусПримечание
dapper

released

1.4.3-5ubuntu0.6
devel

released

1.6.dfsg.1-7
edgy

released

1.4.3-9ubuntu1.5
feisty

released

1.4.4-5ubuntu3.3
upstream

needs-triage

Показывать по

EPSS

Процентиль: 93%
0.11518
Средний

9 Critical

CVSS2

Связанные уязвимости

redhat
больше 18 лет назад

Double free vulnerability in the GSS-API library (lib/gssapi/krb5/k5unseal.c), as used by the Kerberos administration daemon (kadmind) in MIT krb5 before 1.6.1, when used with the authentication method provided by the RPCSEC_GSS RPC library, allows remote authenticated users to execute arbitrary code and modify the Kerberos key database via a message with an "an invalid direction encoding".

nvd
больше 18 лет назад

Double free vulnerability in the GSS-API library (lib/gssapi/krb5/k5unseal.c), as used by the Kerberos administration daemon (kadmind) in MIT krb5 before 1.6.1, when used with the authentication method provided by the RPCSEC_GSS RPC library, allows remote authenticated users to execute arbitrary code and modify the Kerberos key database via a message with an "an invalid direction encoding".

debian
больше 18 лет назад

Double free vulnerability in the GSS-API library (lib/gssapi/krb5/k5un ...

github
больше 3 лет назад

Double free vulnerability in the GSS-API library (lib/gssapi/krb5/k5unseal.c), as used by the Kerberos administration daemon (kadmind) in MIT krb5 before 1.6.1, when used with the authentication method provided by the RPCSEC_GSS RPC library, allows remote authenticated users to execute arbitrary code and modify the Kerberos key database via a message with an "an invalid direction encoding".

oracle-oval
больше 18 лет назад

ELSA-2007-0095: Critical: krb5 security update (CRITICAL)

EPSS

Процентиль: 93%
0.11518
Средний

9 Critical

CVSS2