Lucene search

K
prionPRIOn knowledge basePRION:CVE-2007-2442
HistoryJun 26, 2007 - 10:30 p.m.

Design/Logic Flaw

2007-06-2622:30:00
PRIOn knowledge base
www.prio-n.com
8

7.4 High

AI Score

Confidence

Low

0.966 High

EPSS

Percentile

99.6%

The gssrpc__svcauth_gssapi function in the RPC library in MIT Kerberos 5 (krb5) 1.6.1 and earlier might allow remote attackers to execute arbitrary code via a zero-length RPC credential, which causes kadmind to free an uninitialized pointer during cleanup.

References