Impact
remote code execution
Solution
Please Install the Updated Packages.
Insight
The krb5 telnet daemon allowed remote attackers to skip authentication and gain root access CVE-2007-0956
A bug in the function krb5_klog_syslog() leads to a buffer overflow which could be exploited to execute arbitrary code CVE-2007-0957.
A double-free bug in the GSS-API library could crash kadmind. It's potentially also exploitable to execute arbitrary code CVE-2007-1216.
Affected
krb5 on SUSE LINUX 10.1, openSUSE 10.2, SUSE SLED 10, SUSE SLES 10
References
Updated on 2015-03-25
Severity
Classification
-
CVE CVE-2007-0956, CVE-2007-0957, CVE-2007-1216 -
CVSS Base Score: 9.0
AV:N/AC:L/Au:S/C:C/I:C/A:C
Related Vulnerabilities