CVE-2007-4743

Priority
Untriaged
Description
The original patch for CVE-2007-3999 in svc_auth_gss.c in the RPCSEC_GSS
RPC library in MIT Kerberos 5 (krb5) 1.4 through 1.6.2, as used by the
Kerberos administration daemon (kadmind) and other applications that use
krb5, does not correctly check the buffer length in some environments and
architectures, which might allow remote attackers to conduct a buffer
overflow attack.
References
Notes
kees> Debian package is missing mention of CVE-2007-4743 (and CVE-2007-4000)
Package
Source: krb5 (LP Ubuntu Debian)
Upstream:released (1.5.5, 1.6.3)
Package
Upstream:released (0.16)
More Information

Valid XHTML 1.0 Strict

Updated: 2012-06-01 15:18:12 UTC (commit 5347)