libgssapi before 0.6-13.7, as used by the ISC BIND named daemon in SUSE Linux Enterprise Server 10 SP 1, terminates upon an initialization error, which allows remote attackers to cause a denial of service (daemon exit) via a GSS-TSIG request. NOTE: this issue probably affects other daemons that attempt to initialize this library within a chroot configuration or other invalid configuration.
References
Configurations
History
21 Nov 2024, 00:37
Type | Values Removed | Values Added |
---|---|---|
References | () http://osvdb.org/40935 - | |
References | () http://secunia.com/advisories/27189 - Vendor Advisory | |
References | () http://www.securityfocus.com/bid/26076 - Patch | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/37233 - | |
References | () https://secure-support.novell.com/KanisaPlatform/Publishing/936/3665923_f.SAL_Public.html - Patch |
Information
Published : 2007-10-16 00:17
Updated : 2024-11-21 00:37
NVD link : CVE-2007-5471
Mitre link : CVE-2007-5471
CVE.ORG link : CVE-2007-5471
JSON object : View
Products Affected
suse
- suse_linux
CWE