[Forgot Password]
Login  Register Subscribe

23631

 
 

127000

 
 

102010

 
 

909

 
 

81354

 
 

133

Paid content will be excluded from the download.


Download | Alert*
CVE
view XML view JSON

CVE-2008-0947Date: (C)2008-03-18   (M)2018-02-19


Buffer overflow in the RPC library used by libgssrpc and kadmind in MIT Kerberos 5 (krb5) 1.4 through 1.6.3 allows remote attackers to execute arbitrary code by triggering a large number of open file descriptors.

CVSS V3 Severity:CVSS V2 Severity:
CVSS Score  : CVSS Score  : 10.0
Exploit Score: Exploit Score: 10.0
Impact Score : Impact Score : 10.0
 
CVSS V3 Metrics:CVSS V2 Metrics:
Attack Vector: Access Vector: NETWORK
Attack Complexity: Access Complexity: LOW
Privileges Required: Authentication: NONE
User Interaction: Confidentiality: COMPLETE
Scope: Integrity: COMPLETE
Confidentiality: Availability: COMPLETE
Integrity:  
Availability:  
  





Reference:
SECTRACK-1019631
20080318
http://www.securityfocus.com/archive/1/archive/1/489762/100/0/threaded
http://www.securityfocus.com/archive/1/archive/1/489784/100/0/threaded
http://www.securityfocus.com/archive/1/archive/1/489883/100/0/threaded
BID-28302
SECUNIA-29424
SECUNIA-29428
SECUNIA-29435
SECUNIA-29438
SECUNIA-29451
SECUNIA-29457
SECUNIA-29462
SECUNIA-29464
SECUNIA-29516
SECUNIA-29663
SREASON-3752
ADV-2008-0922
ADV-2008-1102
DSA-1524
FEDORA-2008-2637
FEDORA-2008-2647
GLSA-200803-31
HPSBOV02682
IAVM:2008-B-0024
MDVSA-2008:069
MDVSA-2008:070
RHSA-2008:0164
SSRT100495
SUSE-SA:2008:016
TA08-079B
USN-587-1
VU#374121
http://support.novell.com/docs/Readmes/InfoDocument/patchbuilder/readme_5022520.html
http://support.novell.com/docs/Readmes/InfoDocument/patchbuilder/readme_5022542.html
http://web.mit.edu/kerberos/advisories/MITKRB5-SA-2008-002.txt
http://wiki.rpath.com/Advisories:rPSA-2008-0112
http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0112
krb5-rpclibrary-bo(41273)

CPE    12
cpe:/a:mit:kerberos:5-1.4.4
cpe:/a:mit:kerberos:5-1.5.3
cpe:/a:mit:kerberos:5-1.6.2
cpe:/a:mit:kerberos:5-1.6
...
CWE    1
CWE-119
OVAL    3
oval:org.secpod.oval:def:301322
oval:org.secpod.oval:def:301385
oval:org.mitre.oval:def:8094

© 2013 SecPod Technologies