Vulnerability Description
Buffer overflow in the RPC library used by libgssrpc and kadmind in MIT Kerberos 5 (krb5) 1.4 through 1.6.3 allows remote attackers to execute arbitrary code by triggering a large number of open file descriptors.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mit | Kerberos 5 | 1.4 |
Related Weaknesses (CWE)
References
- http://lists.opensuse.org/opensuse-security-announce/2008-03/msg00006.html
- http://marc.info/?l=bugtraq&m=130497213107107&w=2
- http://secunia.com/advisories/29424
- http://secunia.com/advisories/29428
- http://secunia.com/advisories/29435
- http://secunia.com/advisories/29438
- http://secunia.com/advisories/29451
- http://secunia.com/advisories/29457
- http://secunia.com/advisories/29462
- http://secunia.com/advisories/29464
- http://secunia.com/advisories/29516
- http://secunia.com/advisories/29663
- http://security.gentoo.org/glsa/glsa-200803-31.xml
- http://securityreason.com/securityalert/3752
- http://support.novell.com/docs/Readmes/InfoDocument/patchbuilder/readme_5022520.
FAQ
What is CVE-2008-0947?
CVE-2008-0947 is a vulnerability with a CVSS score of 10.0 (HIGH). Buffer overflow in the RPC library used by libgssrpc and kadmind in MIT Kerberos 5 (krb5) 1.4 through 1.6.3 allows remote attackers to execute arbitrary code by triggering a large number of open file ...
How severe is CVE-2008-0947?
CVE-2008-0947 has been rated HIGH with a CVSS base score of 10.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2008-0947?
Check the references section above for vendor advisories and patch information. Affected products include: Mit Kerberos 5.