CVE-2007-0956: Critical severity MIT Kerberos 5 vulnerability
Published Apr 6, 2007
·Updated
The telnet daemon (telnetd) in MIT krb5 before 1.6.1 allows remote attackers to bypass authentication and gain system access via a username beginning with a '-' character, a similar issue to CVE-2007-0882.
Affected Software
6 affected components
MIT Kerberos 5<1.6.1
Debian Debian Linux=3.1
Debian Debian Linux=4.0
Canonical Ubuntu Linux=6.10
Canonical Ubuntu Linux=5.10
Canonical Ubuntu Linux=6.06
Event History
Apr 6, 2007
CVE Published
01:19 AM
CVE Published
via MITRE·05:00 AM
Data Sourced
via MITRE·05:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-0956?
CVE-2007-0956 is a critical vulnerability that allows remote attackers to bypass authentication in the telnet daemon.
2
How do I fix CVE-2007-0956?
To fix CVE-2007-0956, update to MIT Kerberos 5 version 1.6.1 or later.
3
What systems are affected by CVE-2007-0956?
CVE-2007-0956 affects multiple versions of MIT Kerberos 5 as well as Debian and Ubuntu Linux distributions.
4
Can CVE-2007-0956 be exploited remotely?
Yes, CVE-2007-0956 can be exploited remotely by attackers who send specially crafted usernames.
5
Is CVE-2007-0956 related to any other vulnerabilities?
Yes, CVE-2007-0956 is similar in nature to CVE-2007-0882, both involving authentication bypass issues.