CVE-2007-5894: Critical severity MIT Kerberos 5 vulnerability
DISPUTED The reply function in ftpd.c in the gssftp ftpd in MIT Kerberos 5 (krb5) does not initialize the length variable when authtype has a certain value, which has unknown impact and remote authenticated attack vectors. NOTE: the original disclosure misidentifies the conditions under which the uninitialized variable is used. NOTE: the vendor disputes this issue, stating " The 'length' variable is only uninitialized if 'authtype' is neither the 'KERBEROSV4' nor 'GSSAPI'; this condition cannot occur in the unmodified source code."
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2007-5894?
The severity of CVE-2007-5894 is currently disputed, as the actual impact and attack vectors remain unknown.
How does CVE-2007-5894 affect MIT Kerberos 5?
CVE-2007-5894 affects the reply function in ftpd.c by not initializing a length variable under certain conditions, potentially leading to vulnerabilities.
What versions of MIT Kerberos 5 are affected by CVE-2007-5894?
CVE-2007-5894 affects all versions of MIT Kerberos 5 as identified under the CPE cpe:2.3:a:mit:kerberos_5.
Can CVE-2007-5894 be exploited remotely?
Yes, CVE-2007-5894 has the potential for remote authenticated attack vectors.
What should I do if I am using MIT Kerberos 5 regarding CVE-2007-5894?
If using MIT Kerberos 5, it is advisable to monitor for updates related to CVE-2007-5894 and apply any patches or mitigations provided by the vendor.