9.3
CVSSv2

CVE-2007-5894

Published: 06/12/2007 Updated: 14/05/2024
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
VMScore: 828
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

The reply function in ftpd.c in the gssftp ftpd in MIT Kerberos 5 (krb5) does not initialize the length variable when auth_type has a certain value, which has unknown impact and remote authenticated attack vectors. NOTE: the original disclosure misidentifies the conditions under which the uninitialized variable is used. NOTE: the vendor disputes this issue, stating " The 'length' variable is only uninitialized if 'auth_type' is neither the 'KERBEROS_V4' nor 'GSSAPI'; this condition cannot occur in the unmodified source code.

Vulnerable Product Search on Vulmon Subscribe to Product

mit kerberos 5 -

Vendor Advisories

Debian Bug report logs - #454974 krb5: Venustech AD-LAB CVEs (not serious) Package: krb5; Maintainer for krb5 is Sam Hartman <hartmans@debianorg>; Reported by: Nico Golde <nion@debianorg> Date: Sat, 8 Dec 2007 14:24:02 UTC Severity: normal Tags: fixed-upstream, upstream Found in version 117-1 Fixed in version k ...