CVE-2007-5902: Integer Overflow
Published Dec 6, 2007
·Updated
Integer overflow in the svcauthgssgetprincipal function in lib/rpc/svcauthgss.c in MIT Kerberos 5 (krb5) allows remote attackers to have an unknown impact via a large length value for a GSS client name in an RPC request.
Affected Software
1 affected component
MIT Kerberos 5
Event History
Dec 6, 2007
CVE Published
via MITRE·02:00 AM
Data Sourced
via MITRE·02:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-5902?
CVE-2007-5902 has a moderate severity level due to potential remote exploitation risks.
2
How do I fix CVE-2007-5902?
To fix CVE-2007-5902, update to the latest version of MIT Kerberos 5 that addresses this vulnerability.
3
What type of vulnerability is CVE-2007-5902?
CVE-2007-5902 is an integer overflow vulnerability affecting the svcauth_gss_get_principal function.
4
Who is affected by CVE-2007-5902?
Users of MIT Kerberos 5 who allow remote RPC requests may be affected by CVE-2007-5902.
5
What can attackers potentially do with CVE-2007-5902?
Attackers may exploit CVE-2007-5902 to cause unknown impacts through crafted RPC requests.