CVE-2008-0063: Buffer Overflow
The Kerberos 4 support in KDC in MIT Kerberos 5 (krb5kdc) does not properly clear the unused portion of a buffer when generating an error message, which might allow remote attackers to obtain sensitive information, aka "Uninitialized stack values."
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2008-0063?
CVE-2008-0063 has a medium severity rating due to potential information disclosure vulnerabilities.
How do I fix CVE-2008-0063?
To fix CVE-2008-0063, update your MIT Kerberos 5 to version 1.6.4 or later.
What systems are affected by CVE-2008-0063?
CVE-2008-0063 affects several versions of MIT Kerberos 5 and various Linux distributions including openSUSE and Ubuntu.
Can CVE-2008-0063 be exploited remotely?
Yes, CVE-2008-0063 can be exploited remotely, allowing attackers to potentially access sensitive information.
Is there a patch available for CVE-2008-0063?
Yes, patches are available for CVE-2008-0063 as part of the updates provided by affected distributions.