CVE-2007-3999: Buffer Overflow

Published Aug 6, 2007
·
Updated

MIT notified us of kadmind RPC lib buffer overflow, uninitialized pointer. Will be public on 04 September 2007, at 14:00 US/Eastern time.

This issue has not been triaged as it may well affect recent RHEL distributions with a different severity (flaw type is likely caught by fortifysource)

Other sources

Stack-based buffer overflow in the svcauthgssvalidate function in lib/rpc/svcauthgss.c in the RPCSECGSS RPC library (librpcsecgss) in MIT Kerberos 5 (krb5) 1.4 through 1.6.2, as used by the Kerberos administration daemon (kadmind) and some third-party applications that use krb5, allows remote attackers to cause a denial of service (daemon crash) and probably execute arbitrary code via a long string in an RPC message.

Red Hat

Affected Software

13 affected componentsFixes available
redhat/0.1.7<15.
15.
MIT Kerberos 5=1.4
MIT Kerberos 5=1.4.1
MIT Kerberos 5=1.4.2
MIT Kerberos 5=1.4.3
MIT Kerberos 5=1.4.4
MIT Kerberos 5=1.5
MIT Kerberos 5=1.5.1
MIT Kerberos 5=1.5.2
MIT Kerberos 5=1.5.3
MIT Kerberos 5=1.6
MIT Kerberos 5=1.6.1
MIT Kerberos 5=1.6.2

Event History

Sep 4, 2007
CVE Published
via Red Hat·07:00 PM
Data Sourced
via Red Hat·07:00 PM
RemedyDescriptionSeverityAffected Software
Sep 5, 2007
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description

Parent advisories

This vulnerability appears in the following advisories.

Frequently Asked Questions

1

What is the severity of CVE-2007-3999?

CVE-2007-3999 is classified as a high severity vulnerability due to its potential for remote exploitation via a stack-based buffer overflow.

2

How do I fix CVE-2007-3999?

To fix CVE-2007-3999, update to a patched version of MIT Kerberos 5 beyond 1.6.2 or apply relevant security patches provided by your distribution.

3

Which versions of MIT Kerberos 5 are affected by CVE-2007-3999?

CVE-2007-3999 affects MIT Kerberos 5 versions 1.4 through 1.6.2.

4

What systems are likely to be impacted by CVE-2007-3999?

Systems running MIT Kerberos 5 versions 1.4 to 1.6.2, especially those using the RPCSEC_GSS library, are likely to be impacted.

5

Is CVE-2007-3999 exploitable remotely?

Yes, CVE-2007-3999 is exploitable remotely due to the nature of the buffer overflow vulnerability.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203