Oval Definition:oval:org.mitre.oval:def:22682
Revision Date:2014-05-26Version:20
Title:ELSA-2007:0858: krb5 security update (Important)
Description:The kadm5_modify_policy_internal function in lib/kadm5/srv/svr_policy.c in the Kerberos administration daemon (kadmind) in MIT Kerberos 5 (krb5) 1.5 through 1.6.2 does not properly check return values when the policy does not exist, which might allow remote authenticated users with the "modify policy" privilege to execute arbitrary code via unspecified vectors that trigger a write to an uninitialized pointer.
Family:unixClass:patch
Status:ACCEPTEDReference(s):CVE-2007-3999
CVE-2007-4000
ELSA-2007:0858-01
Platform(s):Oracle Linux 5
Product(s):krb5
Definition Synopsis
  • Oracle Linux 5.x
  • AND rpm test
  • krb5-libs is earlier than 0:1.5-29
  • OR krb5-devel is earlier than 0:1.5-29
  • OR krb5-server is earlier than 0:1.5-29
  • OR krb5 is earlier than 0:1.5-29
  • OR krb5-workstation is earlier than 0:1.5-29
  • BACK