Oval Definition:oval:org.mitre.oval:tst:31053
Comment:krb5-libs is earlier than 0:1.3.4-10
Type:rpminfo_testNamespace:linux
Check_Existence:at_least_one_existsCheck:at least one
State Operator:AND
References
Object:oval:org.mitre.oval:obj:14395
State:oval:org.mitre.oval:ste:9586
Referencing Definitions
Definition IDClassTitleLast Modified
oval:org.mitre.oval:def:11911
V
The add_to_history function in svr_principal.c in libkadm5srv for MIT Kerberos 5 (krb5) up to 1.3.5, when performing a password change, does not properly track the password policy's history count and the maximum number of keys, which can cause an array index out-of-bounds error and may allow authenticated users to execute arbitrary code via a heap-based buffer overflow.
2013-04-29
BACK