CVE-2007-3999: Buffer Overflow
MIT notified us of kadmind RPC lib buffer overflow, uninitialized pointer. Will be public on 04 September 2007, at 14:00 US/Eastern time.
This issue has not been triaged as it may well affect recent RHEL distributions with a different severity (flaw type is likely caught by fortifysource)
Other sources
Stack-based buffer overflow in the svcauthgssvalidate function in lib/rpc/svcauthgss.c in the RPCSECGSS RPC library (librpcsecgss) in MIT Kerberos 5 (krb5) 1.4 through 1.6.2, as used by the Kerberos administration daemon (kadmind) and some third-party applications that use krb5, allows remote attackers to cause a denial of service (daemon crash) and probably execute arbitrary code via a long string in an RPC message.
— Red Hat
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of CVE-2007-3999?
CVE-2007-3999 is classified as a high severity vulnerability due to its potential for remote exploitation via a stack-based buffer overflow.
How do I fix CVE-2007-3999?
To fix CVE-2007-3999, update to a patched version of MIT Kerberos 5 beyond 1.6.2 or apply relevant security patches provided by your distribution.
Which versions of MIT Kerberos 5 are affected by CVE-2007-3999?
CVE-2007-3999 affects MIT Kerberos 5 versions 1.4 through 1.6.2.
What systems are likely to be impacted by CVE-2007-3999?
Systems running MIT Kerberos 5 versions 1.4 to 1.6.2, especially those using the RPCSEC_GSS library, are likely to be impacted.
Is CVE-2007-3999 exploitable remotely?
Yes, CVE-2007-3999 is exploitable remotely due to the nature of the buffer overflow vulnerability.