Vulnerability Description
KDC in MIT Kerberos 5 (krb5kdc) does not set a global variable for some krb4 message types, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted messages that trigger a NULL pointer dereference or double-free.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mit | Kerberos 5 | <= 1.6.3 |
| Debian | Debian Linux | 3.1 |
| Canonical | Ubuntu Linux | 6.06 |
| Fedoraproject | Fedora | 7 |
Related Weaknesses (CWE)
References
- http://docs.info.apple.com/article.html?artnum=307562Broken Link
- http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.htmlMailing List
- http://lists.opensuse.org/opensuse-security-announce/2008-03/msg00006.htmlMailing List
- http://marc.info/?l=bugtraq&m=130497213107107&w=2Mailing List
- http://secunia.com/advisories/29420Broken Link
- http://secunia.com/advisories/29423Broken Link
- http://secunia.com/advisories/29424Broken Link
- http://secunia.com/advisories/29428Broken Link
- http://secunia.com/advisories/29435Broken Link
- http://secunia.com/advisories/29438Broken Link
- http://secunia.com/advisories/29450Broken Link
- http://secunia.com/advisories/29451Broken Link
- http://secunia.com/advisories/29457Broken Link
- http://secunia.com/advisories/29462Broken Link
- http://secunia.com/advisories/29464Broken Link
FAQ
What is CVE-2008-0062?
CVE-2008-0062 is a vulnerability with a CVSS score of 9.8 (CRITICAL). KDC in MIT Kerberos 5 (krb5kdc) does not set a global variable for some krb4 message types, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via c...
How severe is CVE-2008-0062?
CVE-2008-0062 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2008-0062?
Check the references section above for vendor advisories and patch information. Affected products include: Mit Kerberos 5, Debian Debian Linux, Canonical Ubuntu Linux, Fedoraproject Fedora.