CVE-2007-5902 (Kerberos 5) [Sitemap] - HeapOverflow Computer Security Community & Forums : Heap Overflow.com

PDA

View Full Version : CVE-2007-5902 (Kerberos 5)


Heap
06-12-07, 19:56
Integer overflow in the svcauth_gss_get_principal function in lib/rpc/svc_auth_gss.c in MIT Kerberos 5 (krb5) allows remote attackers to have an unknown impact via a large length value for a GSS client name in an RPC request.

More... (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2007-5902)