CVE-2007-2798
Stack-based buffer overflow in the rename_principal_2_svc function in kadmind for MIT Kerberos 1.5.3, 1.6.1, and other versions allows remote authenticated users to execute arbitrary code via a crafted request to rename a principal.
- Affected products
- Gentoo Linux, Hp-Ux, Mit Kerberos, Red Hat, Krb5, Krb5-Devel, Krb5-Libs, Krb5-Server
- Mit Kerberos 5
- ≤ 1.6.1
- Fix
- Available
- CVSS 2.0
- 9.0 HIGH
- EPSS
- 7.5% (94th percentile)
- Weakness
- CWE-787
- NVD status
- Modified
- Published
- 2007-06-26
CVE-2007-2798 at NVD
1 known exploit for CVE-2007-2798
Proof-of-concept code and exploit modules indexed by Sploitus