Vulnerability Description
The telnet daemon (telnetd) in MIT krb5 before 1.6.1 allows remote attackers to bypass authentication and gain system access via a username beginning with a '-' character, a similar issue to CVE-2007-0882.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mit | Kerberos 5 | < 1.6.1 |
| Debian | Debian Linux | 3.1 |
| Canonical | Ubuntu Linux | 5.10 |
Related Weaknesses (CWE)
References
- ftp://patches.sgi.com/support/free/security/advisories/20070401-01-P.ascBroken Link
- http://lists.suse.com/archive/suse-security-announce/2007-Apr/0001.htmlBroken Link
- http://secunia.com/advisories/24706Third Party Advisory
- http://secunia.com/advisories/24735Third Party Advisory
- http://secunia.com/advisories/24736Third Party Advisory
- http://secunia.com/advisories/24740Third Party Advisory
- http://secunia.com/advisories/24750Third Party Advisory
- http://secunia.com/advisories/24755Third Party Advisory
- http://secunia.com/advisories/24757Third Party Advisory
- http://secunia.com/advisories/24785Third Party Advisory
- http://secunia.com/advisories/24786Third Party Advisory
- http://secunia.com/advisories/24817Third Party Advisory
- http://security.gentoo.org/glsa/glsa-200704-02.xmlThird Party Advisory
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-102867-1Broken Link
- http://web.mit.edu/kerberos/www/advisories/MITKRB5-SA-2007-001-telnetd.txtVendor Advisory
FAQ
What is CVE-2007-0956?
CVE-2007-0956 is a vulnerability with a CVSS score of 10.0 (HIGH). The telnet daemon (telnetd) in MIT krb5 before 1.6.1 allows remote attackers to bypass authentication and gain system access via a username beginning with a '-' character, a similar issue to CVE-2007-...
How severe is CVE-2007-0956?
CVE-2007-0956 has been rated HIGH with a CVSS base score of 10.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2007-0956?
Check the references section above for vendor advisories and patch information. Affected products include: Mit Kerberos 5, Debian Debian Linux, Canonical Ubuntu Linux.