CVE Vulnerabilities

CVE-2007-2443

Published: Jun 26, 2007 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
8.3 HIGH
AV:A/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Integer signedness error in the gssrpc__svcauth_unix function in svc_auth_unix.c in the RPC library in MIT Kerberos 5 (krb5) 1.6.1 and earlier might allow remote attackers to execute arbitrary code via a negative length value.

Affected Software

NameVendorStart VersionEnd Version
Kerberos_5Mit*1.6.1 (including)
Red Hat Enterprise Linux 2.1RedHatkrb5-0:1.2.2-47*
Red Hat Enterprise Linux 3RedHatkrb5-0:1.2.7-66*
Red Hat Enterprise Linux 4RedHatkrb5-0:1.3.4-49*
Red Hat Enterprise Linux 5RedHatkrb5-0:1.5-26*
Krb5Ubuntudapper*
Krb5Ubuntudevel*
Krb5Ubuntuedgy*
Krb5Ubuntufeisty*

References