HIGH · 9.0

CVE-2007-2798

Stack-based buffer overflow in the rename_principal_2_svc function in kadmind for MIT Kerberos 1.5.3, 1.6.1, and other versions allows remote authenticated users to execute arbitrary code via a crafte...

Vulnerability Description

Stack-based buffer overflow in the rename_principal_2_svc function in kadmind for MIT Kerberos 1.5.3, 1.6.1, and other versions allows remote authenticated users to execute arbitrary code via a crafted request to rename a principal.

CVSS Score

9.0

HIGH

AV:N/AC:L/Au:S/C:C/I:C/A:C
Confidentiality
COMPLETE
Integrity
COMPLETE
Availability
COMPLETE

Affected Products

VendorProductVersions
MitKerberos 5<= 1.6.1
CanonicalUbuntu Linux6.06
DebianDebian Linux3.1

Related Weaknesses (CWE)

References

FAQ

What is CVE-2007-2798?

CVE-2007-2798 is a vulnerability with a CVSS score of 9.0 (HIGH). Stack-based buffer overflow in the rename_principal_2_svc function in kadmind for MIT Kerberos 1.5.3, 1.6.1, and other versions allows remote authenticated users to execute arbitrary code via a crafte...

How severe is CVE-2007-2798?

CVE-2007-2798 has been rated HIGH with a CVSS base score of 9.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2007-2798?

Check the references section above for vendor advisories and patch information. Affected products include: Mit Kerberos 5, Canonical Ubuntu Linux, Debian Debian Linux.