CVE-2007-0957 : Detail

CVE-2007-0957

Overflow
13.22%V4
Network
2007-04-05
23h00 +00:00
2018-10-16
12h57 +00:00
Notifications for a CVE
Stay informed of any changes for a specific CVE.
Notifications manage

CVE Descriptions

Stack-based buffer overflow in the krb5_klog_syslog function in the kadm5 library, as used by the Kerberos administration daemon (kadmind) and Key Distribution Center (KDC), in MIT krb5 before 1.6.1 allows remote authenticated users to execute arbitrary code and modify the Kerberos key database via crafted arguments, possibly involving certain format string specifiers.

CVE Informations

Related Weaknesses

CWE-ID Weakness Name Source
CWE-787 Out-of-bounds Write
The product writes data past the end, or before the beginning, of the intended buffer.

Metrics

Metrics Score Severity CVSS Vector Source
V2 9 AV:N/AC:L/Au:S/C:C/I:C/A:C nvd@nist.gov

EPSS

EPSS is a scoring model that predicts the likelihood of a vulnerability being exploited.

EPSS Score

The EPSS model produces a probability score between 0 and 1 (0 and 100%). The higher the score, the greater the probability that a vulnerability will be exploited.

EPSS Percentile

The percentile is used to rank CVE according to their EPSS score. For example, a CVE in the 95th percentile according to its EPSS score is more likely to be exploited than 95% of other CVE. Thus, the percentile is used to compare the EPSS score of a CVE with that of other CVE.

Products Mentioned

Configuraton 0

Mit>>Kerberos_5 >> Version To (excluding) 1.6.1

Configuraton 0

Debian>>Debian_linux >> Version 3.1

Debian>>Debian_linux >> Version 4.0

Configuraton 0

Canonical>>Ubuntu_linux >> Version 5.10

Canonical>>Ubuntu_linux >> Version 6.06

Canonical>>Ubuntu_linux >> Version 6.10

References

http://www.vupen.com/english/advisories/2007/1218
Tags : vdb-entry, x_refsource_VUPEN
http://secunia.com/advisories/24966
Tags : third-party-advisory, x_refsource_SECUNIA
http://secunia.com/advisories/24706
Tags : third-party-advisory, x_refsource_SECUNIA
http://secunia.com/advisories/24798
Tags : third-party-advisory, x_refsource_SECUNIA
http://secunia.com/advisories/24740
Tags : third-party-advisory, x_refsource_SECUNIA
http://www.redhat.com/support/errata/RHSA-2007-0095.html
Tags : vendor-advisory, x_refsource_REDHAT
http://www.vupen.com/english/advisories/2007/1983
Tags : vdb-entry, x_refsource_VUPEN
http://secunia.com/advisories/24786
Tags : third-party-advisory, x_refsource_SECUNIA
http://sunsolve.sun.com/search/document.do?assetkey=1-26-102930-1
Tags : vendor-advisory, x_refsource_SUNALERT
http://www.us-cert.gov/cas/techalerts/TA07-093B.html
Tags : third-party-advisory, x_refsource_CERT
http://www.debian.org/security/2007/dsa-1276
Tags : vendor-advisory, x_refsource_DEBIAN
http://secunia.com/advisories/24735
Tags : third-party-advisory, x_refsource_SECUNIA
http://www.securityfocus.com/bid/23285
Tags : vdb-entry, x_refsource_BID
http://www.us-cert.gov/cas/techalerts/TA07-109A.html
Tags : third-party-advisory, x_refsource_CERT
http://secunia.com/advisories/24750
Tags : third-party-advisory, x_refsource_SECUNIA
http://www.vupen.com/english/advisories/2007/1250
Tags : vdb-entry, x_refsource_VUPEN
http://secunia.com/advisories/24817
Tags : third-party-advisory, x_refsource_SECUNIA
http://secunia.com/advisories/24757
Tags : third-party-advisory, x_refsource_SECUNIA
http://www.kb.cert.org/vuls/id/704024
Tags : third-party-advisory, x_refsource_CERT-VN
http://www.securitytracker.com/id?1017849
Tags : vdb-entry, x_refsource_SECTRACK
http://secunia.com/advisories/24785
Tags : third-party-advisory, x_refsource_SECUNIA
http://secunia.com/advisories/25464
Tags : third-party-advisory, x_refsource_SECUNIA
http://www.mandriva.com/security/advisories?name=MDKSA-2007:077
Tags : vendor-advisory, x_refsource_MANDRIVA
http://www.ubuntu.com/usn/usn-449-1
Tags : vendor-advisory, x_refsource_UBUNTU
http://www.vupen.com/english/advisories/2007/1470
Tags : vdb-entry, x_refsource_VUPEN
http://secunia.com/advisories/24736
Tags : third-party-advisory, x_refsource_SECUNIA
http://security.gentoo.org/glsa/glsa-200704-02.xml
Tags : vendor-advisory, x_refsource_GENTOO