Lucene search

K
ubuntuUbuntuUSN-449-1
HistoryApr 04, 2007 - 12:00 a.m.

krb5 vulnerabilities

2007-04-0400:00:00
ubuntu.com
43

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

AI Score

7.3

Confidence

Low

EPSS

0.967

Percentile

99.7%

Releases

  • Ubuntu 6.10
  • Ubuntu 6.06
  • Ubuntu 5.10

Details

The krb5 telnet service did not appropriately verify user names. A
remote attacker could log in as the root user by requesting a specially
crafted user name. (CVE-2007-0956)

The krb5 syslog library did not correctly verify the size of log
messages. A remote attacker could send a specially crafted message and
execute arbitrary code with root privileges. (CVE-2007-0957)

The krb5 administration service was vulnerable to a double-free in the
GSS RPC library. A remote attacker could send a specially crafted
request and execute arbitrary code with root privileges. (CVE-2007-1216)

OSVersionArchitecturePackageVersionFilename
Ubuntu6.10noarchkrb5-telnetd< 1.4.3-9ubuntu1.2UNKNOWN
Ubuntu6.10noarchlibkrb53< 1.4.3-9ubuntu1.2UNKNOWN
Ubuntu6.10noarchlibkadm55< 1.4.3-9ubuntu1.2UNKNOWN
Ubuntu6.06noarchkrb5-telnetd< 1.4.3-5ubuntu0.3UNKNOWN
Ubuntu6.06noarchlibkrb53< 1.4.3-5ubuntu0.3UNKNOWN
Ubuntu6.06noarchlibkadm55< 1.4.3-5ubuntu0.3UNKNOWN
Ubuntu5.10noarchkrb5-telnetd< 1.3.6-4ubuntu0.2UNKNOWN
Ubuntu5.10noarchlibkrb53< 1.3.6-4ubuntu0.2UNKNOWN
Ubuntu5.10noarchlibkadm55< 1.3.6-4ubuntu0.2UNKNOWN

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

AI Score

7.3

Confidence

Low

EPSS

0.967

Percentile

99.7%