← All CVEs

CVE-2007-2442

high · 10

The gssrpc__svcauth_gssapi function in the RPC library in MIT Kerberos 5 (krb5) 1.6.1 and earlier might allow remote attackers to execute arbitrary code via a zero-length RPC credential, which causes kadmind to free an uninitialized pointer during cleanup.

10
CVSS
11.4%
EPSS (exploit prob.)
96th
EPSS percentile
2007-06-26
Published

AV:N/AC:L/Au:N/C:C/I:C/A:C

Weaknesses

CWE-824

Affected products

VendorProductAffected versions
mitkerberos_5<= 1.6.1
debiandebian_linux3.1
debiandebian_linux4.0
canonicalubuntu_linux6.06
canonicalubuntu_linux6.10
canonicalubuntu_linux7.04

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2007-2442