HIGH · 9.3

CVE-2006-6143

The RPC library in Kerberos 5 1.4 through 1.4.4, and 1.5 through 1.5.1, as used in Kerberos administration daemon (kadmind) and other products that use this library, calls an uninitialized function po...

Vulnerability Description

The RPC library in Kerberos 5 1.4 through 1.4.4, and 1.5 through 1.5.1, as used in Kerberos administration daemon (kadmind) and other products that use this library, calls an uninitialized function pointer in freed memory, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unspecified vectors.

CVSS Score

9.3

HIGH

AV:N/AC:M/Au:N/C:C/I:C/A:C
Confidentiality
COMPLETE
Integrity
COMPLETE
Availability
COMPLETE

Affected Products

VendorProductVersions
MitKerberos 51.4
CanonicalUbuntu Linux6.06

Related Weaknesses (CWE)

References

FAQ

What is CVE-2006-6143?

CVE-2006-6143 is a vulnerability with a CVSS score of 9.3 (HIGH). The RPC library in Kerberos 5 1.4 through 1.4.4, and 1.5 through 1.5.1, as used in Kerberos administration daemon (kadmind) and other products that use this library, calls an uninitialized function po...

How severe is CVE-2006-6143?

CVE-2006-6143 has been rated HIGH with a CVSS base score of 9.3/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2006-6143?

Check the references section above for vendor advisories and patch information. Affected products include: Mit Kerberos 5, Canonical Ubuntu Linux.