Vulnerability Description
Buffer overflow in the RPC library (lib/rpc/rpc_dtablesize.c) used by libgssrpc and kadmind in MIT Kerberos 5 (krb5) 1.2.2, and probably other versions before 1.3, when running on systems whose unistd.h does not define the FD_SETSIZE macro, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code by triggering a large number of open file descriptors.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mit | Kerberos 5 | 1.2.2 |
Related Weaknesses (CWE)
References
- http://lists.opensuse.org/opensuse-security-announce/2008-03/msg00006.html
- http://marc.info/?l=bugtraq&m=130497213107107&w=2
- http://secunia.com/advisories/29423
- http://secunia.com/advisories/29424
- http://secunia.com/advisories/29428Vendor Advisory
- http://secunia.com/advisories/29663
- http://secunia.com/advisories/30535
- http://securityreason.com/securityalert/3752
- http://support.novell.com/docs/Readmes/InfoDocument/patchbuilder/readme_5022520.
- http://support.novell.com/docs/Readmes/InfoDocument/patchbuilder/readme_5022542.
- http://web.mit.edu/kerberos/advisories/MITKRB5-SA-2008-002.txt
- http://www.kb.cert.org/vuls/id/374121US Government Resource
- http://www.redhat.com/support/errata/RHSA-2008-0181.html
- http://www.securityfocus.com/archive/1/489762/100/0/threaded
- http://www.securityfocus.com/archive/1/489784/100/0/threaded
FAQ
What is CVE-2008-0948?
CVE-2008-0948 is a vulnerability with a CVSS score of 9.3 (HIGH). Buffer overflow in the RPC library (lib/rpc/rpc_dtablesize.c) used by libgssrpc and kadmind in MIT Kerberos 5 (krb5) 1.2.2, and probably other versions before 1.3, when running on systems whose unistd...
How severe is CVE-2008-0948?
CVE-2008-0948 has been rated HIGH with a CVSS base score of 9.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2008-0948?
Check the references section above for vendor advisories and patch information. Affected products include: Mit Kerberos 5.