CVE-2008-0947: Buffer Overflow
Published Mar 19, 2008
·Updated
Buffer overflow in the RPC library used by libgssrpc and kadmind in MIT Kerberos 5 (krb5) 1.4 through 1.6.3 allows remote attackers to execute arbitrary code by triggering a large number of open file descriptors.
Affected Software
13 affected components
MIT Kerberos 5=1.4
MIT Kerberos 5=1.4.1
MIT Kerberos 5=1.4.2
MIT Kerberos 5=1.4.3
MIT Kerberos 5=1.4.4
MIT Kerberos 5=1.5
MIT Kerberos 5=1.5.1
MIT Kerberos 5=1.5.2
MIT Kerberos 5=1.5.3
MIT Kerberos 5=1.6
MIT Kerberos 5=1.6.1
MIT Kerberos 5=1.6.2
MIT Kerberos 5=1.6.3
Event History
Mar 19, 2008
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2008-0947?
CVE-2008-0947 is considered a high severity vulnerability due to the potential for remote code execution.
2
How do I fix CVE-2008-0947?
To fix CVE-2008-0947, upgrade your MIT Kerberos 5 installation to version 1.6.4 or later.
3
Which versions of MIT Kerberos 5 are affected by CVE-2008-0947?
CVE-2008-0947 affects MIT Kerberos 5 versions 1.4 through 1.6.3.
4
Can CVE-2008-0947 be exploited remotely?
Yes, CVE-2008-0947 can be exploited remotely by attackers triggering a large number of open file descriptors.
5
What is the impact of CVE-2008-0947 on systems?
The impact of CVE-2008-0947 includes potential arbitrary code execution, leading to unauthorized access or control of the affected system.