← All CVEs

CVE-2007-3999

high · 10

Stack-based buffer overflow in the svcauth_gss_validate function in lib/rpc/svc_auth_gss.c in the RPCSEC_GSS RPC library (librpcsecgss) in MIT Kerberos 5 (krb5) 1.4 through 1.6.2, as used by the Kerberos administration daemon (kadmind) and some third-party applications that use krb5, allows remote attackers to cause a denial of service (daemon crash) and probably execute arbitrary code via a long string in an RPC message.

10
CVSS
11.0%
EPSS (exploit prob.)
96th
EPSS percentile
2007-09-05
Published

AV:N/AC:L/Au:N/C:C/I:C/A:C

Weaknesses

CWE-119

Affected products

VendorProductAffected versions
mitkerberos_51.4
mitkerberos_51.4.1
mitkerberos_51.4.2
mitkerberos_51.4.3
mitkerberos_51.4.4
mitkerberos_51.5
mitkerberos_51.5.1
mitkerberos_51.5.2
mitkerberos_51.5.3
mitkerberos_51.6
mitkerberos_51.6.1
mitkerberos_51.6.2

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2007-3999