Lucene search

K
cve[email protected]CVE-2007-5901
HistoryDec 06, 2007 - 2:46 a.m.

CVE-2007-5901

2007-12-0602:46:00
CWE-399
web.nvd.nist.gov
26
cve
2007
5901
use-after-free
vulnerability
gss_indicate_mechs
mit
kerberos 5
nvd

6.9 Medium

CVSS2

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:M/Au:N/C:C/I:C/A:C

7.7 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

47.3%

Use-after-free vulnerability in the gss_indicate_mechs function in lib/gssapi/mechglue/g_initialize.c in MIT Kerberos 5 (krb5) has unknown impact and attack vectors. NOTE: this might be the result of a typo in the source code.

Affected configurations

NVD
Node
applemac_os_xMatch10.4.11
OR
applemac_os_xMatch10.5.2
OR
applemac_os_x_serverMatch10.4.11
OR
applemac_os_x_serverMatch10.5.2
AND
mitkerberos_5Range1.6.3_kdc

References

6.9 Medium

CVSS2

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:M/Au:N/C:C/I:C/A:C

7.7 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

47.3%