CVE Vulnerabilities

CVE-2007-5894

Published: Dec 06, 2007 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
9.3 HIGH
AV:N/AC:M/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
NEGLIGIBLE
root.io logo minimus.io logo echo.ai logo

The reply function in ftpd.c in the gssftp ftpd in MIT Kerberos 5 (krb5) does not initialize the length variable when auth_type has a certain value, which has unknown impact and remote authenticated attack vectors. NOTE: the original disclosure misidentifies the conditions under which the uninitialized variable is used. NOTE: the vendor disputes this issue, stating The length variable is only uninitialized if auth_type is neither the KERBEROS_V4 nor GSSAPI; this condition cannot occur in the unmodified source code.

Affected Software

NameVendorStart VersionEnd Version
Kerberos_5Mit- (including)- (including)
Krb5Ubuntudapper*
Krb5Ubuntuedgy*
Krb5Ubuntufeisty*
Krb5Ubuntugutsy*
Krb5Ubuntuhardy*
Krb5Ubuntuupstream*

References