First published: Thu Dec 06 2007(Updated: )
Use-after-free vulnerability in the gss_indicate_mechs function in lib/gssapi/mechglue/g_initialize.c in MIT Kerberos 5 (krb5) has unknown impact and attack vectors. NOTE: this might be the result of a typo in the source code.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apple iOS and macOS | =10.4.11 | |
Apple iOS and macOS | =10.5.2 | |
Apple macOS Server | =10.4.11 | |
Apple macOS Server | =10.5.2 | |
MIT Kerberos 5 Application | <=1.6.3_kdc |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2007-5901 is currently unknown due to the lack of detailed information on its impact and attack vectors.
CVE-2007-5901 affects MIT Kerberos 5 versions up to and including 1.6.3_kdc.
To mitigate CVE-2007-5901, update to a version of MIT Kerberos 5 that is later than 1.6.3_kdc.
Yes, patches for CVE-2007-5901 are available in later versions of MIT Kerberos 5.
CVE-2007-5901 is a use-after-free vulnerability found in the gss_indicate_mechs function.