CVE-2008-0062
critical · 9.8KDC in MIT Kerberos 5 (krb5kdc) does not set a global variable for some krb4 message types, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted messages that trigger a NULL pointer dereference or double-free.
9.8
CVSS
10.1%
EPSS (exploit prob.)
95th
EPSS percentile
2008-03-19
Published
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-665
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| mit | kerberos_5 | <= 1.6.3 |
| debian | debian_linux | 3.1 |
| debian | debian_linux | 4.0 |
| canonical | ubuntu_linux | 6.06 |
| canonical | ubuntu_linux | 6.10 |
| canonical | ubuntu_linux | 7.04 |
| canonical | ubuntu_linux | 7.10 |
| fedoraproject | fedora | 7 |
| fedoraproject | fedora | 8 |
Check a specific version with /api/v1/cve/match.
References
- http://docs.info.apple.com/article.html?artnum=307562
- http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html
- http://lists.opensuse.org/opensuse-security-announce/2008-03/msg00006.html
- http://marc.info/?l=bugtraq&m=130497213107107&w=2
- http://secunia.com/advisories/29420
- http://secunia.com/advisories/29423
- http://secunia.com/advisories/29424
- http://secunia.com/advisories/29428
- http://secunia.com/advisories/29435
- http://secunia.com/advisories/29438
- http://secunia.com/advisories/29450
- http://secunia.com/advisories/29451
- http://secunia.com/advisories/29457
- http://secunia.com/advisories/29462
- http://secunia.com/advisories/29464
- http://secunia.com/advisories/29516
- http://secunia.com/advisories/29663
- http://secunia.com/advisories/30535
- http://support.novell.com/docs/Readmes/InfoDocument/patchbuilder/readme_5022520.html
- http://support.novell.com/docs/Readmes/InfoDocument/patchbuilder/readme_5022542.html
- http://web.mit.edu/kerberos/advisories/MITKRB5-SA-2008-001.txt
- http://wiki.rpath.com/Advisories:rPSA-2008-0112
- http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0112
- http://www.debian.org/security/2008/dsa-1524
- http://www.gentoo.org/security/en/glsa/glsa-200803-31.xml
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2008-0062