TROYANOSYVIRUS
Back to CVEs

CVE-2007-3999

N/A

Description

Stack-based buffer overflow in the svcauth_gss_validate function in lib/rpc/svc_auth_gss.c in the RPCSEC_GSS RPC library (librpcsecgss) in MIT Kerberos 5 (krb5) 1.4 through 1.6.2, as used by the Kerberos administration daemon (kadmind) and some third-party applications that use krb5, allows remote attackers to cause a denial of service (daemon crash) and probably execute arbitrary code via a long string in an RPC message.

CVE Details

CVSS v3.1 ScoreN/A
Published9/5/2007
Last Modified4/23/2026
Sourcenvd
Honeypot Sightings0

Affected Products

mit:kerberos_5

Weaknesses (CWE)

CWE-119

References

http://docs.info.apple.com/article.html?artnum=307041(af854a3a-2127-422b-91ae-364da2661108)
http://secunia.com/advisories/26676(af854a3a-2127-422b-91ae-364da2661108)
http://secunia.com/advisories/26680(af854a3a-2127-422b-91ae-364da2661108)
http://secunia.com/advisories/26684(af854a3a-2127-422b-91ae-364da2661108)
http://secunia.com/advisories/26691(af854a3a-2127-422b-91ae-364da2661108)
http://secunia.com/advisories/26697(af854a3a-2127-422b-91ae-364da2661108)
http://secunia.com/advisories/26699(af854a3a-2127-422b-91ae-364da2661108)
http://secunia.com/advisories/26700(af854a3a-2127-422b-91ae-364da2661108)
http://secunia.com/advisories/26705(af854a3a-2127-422b-91ae-364da2661108)
http://secunia.com/advisories/26713(af854a3a-2127-422b-91ae-364da2661108)
http://secunia.com/advisories/26728(af854a3a-2127-422b-91ae-364da2661108)
http://secunia.com/advisories/26783(af854a3a-2127-422b-91ae-364da2661108)
http://secunia.com/advisories/26792(af854a3a-2127-422b-91ae-364da2661108)
http://secunia.com/advisories/26822(af854a3a-2127-422b-91ae-364da2661108)
http://secunia.com/advisories/26896(af854a3a-2127-422b-91ae-364da2661108)
http://secunia.com/advisories/26987(af854a3a-2127-422b-91ae-364da2661108)
http://secunia.com/advisories/27043(af854a3a-2127-422b-91ae-364da2661108)
http://secunia.com/advisories/27081(af854a3a-2127-422b-91ae-364da2661108)
http://secunia.com/advisories/27146(af854a3a-2127-422b-91ae-364da2661108)
http://secunia.com/advisories/27643(af854a3a-2127-422b-91ae-364da2661108)
http://secunia.com/advisories/27756(af854a3a-2127-422b-91ae-364da2661108)
http://secunia.com/advisories/29247(af854a3a-2127-422b-91ae-364da2661108)
http://secunia.com/advisories/29270(af854a3a-2127-422b-91ae-364da2661108)
http://security.gentoo.org/glsa/glsa-200710-01.xml(af854a3a-2127-422b-91ae-364da2661108)
http://securityreason.com/securityalert/3092(af854a3a-2127-422b-91ae-364da2661108)
http://www.debian.org/security/2007/dsa-1367(af854a3a-2127-422b-91ae-364da2661108)
http://www.debian.org/security/2007/dsa-1368(af854a3a-2127-422b-91ae-364da2661108)
http://www.gentoo.org/security/en/glsa/glsa-200709-01.xml(af854a3a-2127-422b-91ae-364da2661108)
http://www.kb.cert.org/vuls/id/883632(af854a3a-2127-422b-91ae-364da2661108)
http://www.redhat.com/support/errata/RHSA-2007-0858.html(af854a3a-2127-422b-91ae-364da2661108)
http://www.redhat.com/support/errata/RHSA-2007-0913.html(af854a3a-2127-422b-91ae-364da2661108)
http://www.redhat.com/support/errata/RHSA-2007-0951.html(af854a3a-2127-422b-91ae-364da2661108)
http://www.securityfocus.com/bid/25534(af854a3a-2127-422b-91ae-364da2661108)
http://www.securityfocus.com/bid/26444(af854a3a-2127-422b-91ae-364da2661108)
http://www.securitytracker.com/id?1018647(af854a3a-2127-422b-91ae-364da2661108)
http://www.trustix.org/errata/2007/0026/(af854a3a-2127-422b-91ae-364da2661108)
http://www.ubuntu.com/usn/usn-511-1(af854a3a-2127-422b-91ae-364da2661108)
http://www.us-cert.gov/cas/techalerts/TA07-319A.html(af854a3a-2127-422b-91ae-364da2661108)
http://www.vupen.com/english/advisories/2007/3051(af854a3a-2127-422b-91ae-364da2661108)
http://www.vupen.com/english/advisories/2007/3052(af854a3a-2127-422b-91ae-364da2661108)
http://www.vupen.com/english/advisories/2007/3060(af854a3a-2127-422b-91ae-364da2661108)
http://www.vupen.com/english/advisories/2007/3868(af854a3a-2127-422b-91ae-364da2661108)
https://bugzilla.redhat.com/show_bug.cgi?id=250973(af854a3a-2127-422b-91ae-364da2661108)

IOC Correlations

No correlations recorded

This product uses data from the NVD API but is not endorsed or certified by the NVD.