CVE-2007-2798: Buffer Overflow
Published Jun 26, 2007
·Updated
Stack-based buffer overflow in the renameprincipal2svc function in kadmind for MIT Kerberos 1.5.3, 1.6.1, and other versions allows remote authenticated users to execute arbitrary code via a crafted request to rename a principal.
Affected Software
6 affected components
MIT Kerberos 5<=1.6.1
Canonical Ubuntu Linux=7.04
Canonical Ubuntu Linux=6.10
Canonical Ubuntu Linux=6.06
Debian Debian Linux=3.1
Debian Debian Linux=4.0
Remediation
Patch Available
Event History
Jun 26, 2007
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-2798?
CVE-2007-2798 is considered a critical vulnerability due to its potential to allow remote authenticated users to execute arbitrary code.
2
How do I fix CVE-2007-2798?
To fix CVE-2007-2798, you should upgrade to a patched version of MIT Kerberos or the affected operating systems.
3
What versions of MIT Kerberos are affected by CVE-2007-2798?
CVE-2007-2798 affects MIT Kerberos versions 1.5.3, 1.6.1, and earlier versions.
4
Can CVE-2007-2798 be exploited remotely?
Yes, CVE-2007-2798 can be exploited remotely by authenticated users through a crafted request.
5
Which operating systems are impacted by CVE-2007-2798?
Operating systems impacted by CVE-2007-2798 include certain versions of Ubuntu and Debian Linux.