Lucene search

K
nvd[email protected]NVD:CVE-2007-0956
HistoryApr 06, 2007 - 1:19 a.m.

CVE-2007-0956

2007-04-0601:19:00
CWE-306
web.nvd.nist.gov

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

AI Score

6.9

Confidence

Low

EPSS

0.844

Percentile

98.5%

The telnet daemon (telnetd) in MIT krb5 before 1.6.1 allows remote attackers to bypass authentication and gain system access via a username beginning with a ‘-’ character, a similar issue to CVE-2007-0882.

Affected configurations

NVD
Node
mitkerberos_5Range<1.6.1
Node
debiandebian_linuxMatch3.1
OR
debiandebian_linuxMatch4.0
Node
canonicalubuntu_linuxMatch5.10
OR
canonicalubuntu_linuxMatch6.06
OR
canonicalubuntu_linuxMatch6.10

References

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

AI Score

6.9

Confidence

Low

EPSS

0.844

Percentile

98.5%