CVE Vulnerabilities

CVE-2007-5902

Published: Dec 06, 2007 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
10 HIGH
AV:N/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
LOW
root.io logo minimus.io logo echo.ai logo

Integer overflow in the svcauth_gss_get_principal function in lib/rpc/svc_auth_gss.c in MIT Kerberos 5 (krb5) allows remote attackers to have an unknown impact via a large length value for a GSS client name in an RPC request.

Affected Software

NameVendorStart VersionEnd Version
Kerberos_5Mit- (including)- (including)
Krb5Ubuntudapper*
Krb5Ubuntuedgy*
Krb5Ubuntufeisty*
Krb5Ubuntugutsy*
Krb5Ubuntuhardy*
Krb5Ubuntuupstream*

References