First published: Mon Aug 06 2007(Updated: )
MIT notified us of a kadmind uninitialized pointer. Will be public on 04 September 2007, at 14:00 US/Eastern time. This issue has not been triaged as it may well affect recent RHEL distributions with a different severity (flaw type is likely caught by fortify_source)
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
MIT Kerberos 5 | =1.5 | |
MIT Kerberos 5 | =1.5.1 | |
MIT Kerberos 5 | =1.5.2 | |
MIT Kerberos 5 | =1.5.3 | |
MIT Kerberos 5 | =1.6 | |
MIT Kerberos 5 | =1.6.1 | |
MIT Kerberos 5 | =1.6.2 | |
MIT Kerberos 5 | >=1.5<=1.6.2 | |
Fedora | =7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-4000 has not been explicitly triaged but may affect recent RHEL distributions with varying severity due to its nature.
To fix CVE-2007-4000, users should apply the latest updates for MIT Kerberos 5 or consult their distribution's advisories.
CVE-2007-4000 affects multiple versions of MIT Kerberos 5, including 1.5 through 1.6.2 and Fedora 7.
The nature of CVE-2007-4000 suggests that it could be potentially exploited remotely, depending on configuration.
CVE-2007-4000 was reported by security researchers at MIT.