CVE-2007-5901

Use-after-free vulnerability in the gss_indicate_mechs function in lib/gssapi/mechglue/g_initialize.c in MIT Kerberos 5 (krb5) has unknown impact and attack vectors. NOTE: this might be the result of a typo in the source code.
References
Link Resource
http://bugs.gentoo.org/show_bug.cgi?id=199214 Exploit
http://docs.info.apple.com/article.html?artnum=307562
http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html
http://osvdb.org/43346
http://seclists.org/fulldisclosure/2007/Dec/0176.html
http://seclists.org/fulldisclosure/2007/Dec/0321.html
http://secunia.com/advisories/29451
http://secunia.com/advisories/29464
http://secunia.com/advisories/29516
http://secunia.com/advisories/39290
http://security.gentoo.org/glsa/glsa-200803-31.xml
http://ubuntu.com/usn/usn-924-1
http://www.mandriva.com/security/advisories?name=MDVSA-2008:069
http://www.redhat.com/support/errata/RHSA-2008-0164.html
http://www.securityfocus.com/bid/26750 Patch
http://www.vupen.com/english/advisories/2008/0924/references
https://issues.rpath.com/browse/RPL-2012
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11451
https://www.redhat.com/archives/fedora-package-announce/2008-March/msg00537.html
https://www.redhat.com/archives/fedora-package-announce/2008-March/msg00544.html
http://bugs.gentoo.org/show_bug.cgi?id=199214 Exploit
http://docs.info.apple.com/article.html?artnum=307562
http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html
http://osvdb.org/43346
http://seclists.org/fulldisclosure/2007/Dec/0176.html
http://seclists.org/fulldisclosure/2007/Dec/0321.html
http://secunia.com/advisories/29451
http://secunia.com/advisories/29464
http://secunia.com/advisories/29516
http://secunia.com/advisories/39290
http://security.gentoo.org/glsa/glsa-200803-31.xml
http://ubuntu.com/usn/usn-924-1
http://www.mandriva.com/security/advisories?name=MDVSA-2008:069
http://www.redhat.com/support/errata/RHSA-2008-0164.html
http://www.securityfocus.com/bid/26750 Patch
http://www.vupen.com/english/advisories/2008/0924/references
https://issues.rpath.com/browse/RPL-2012
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11451
https://www.redhat.com/archives/fedora-package-announce/2008-March/msg00537.html
https://www.redhat.com/archives/fedora-package-announce/2008-March/msg00544.html
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:o:apple:mac_os_x:10.4.11:*:*:*:*:*:*:*
cpe:2.3:o:apple:mac_os_x:10.5.2:*:*:*:*:*:*:*
cpe:2.3:o:apple:mac_os_x_server:10.4.11:*:*:*:*:*:*:*
cpe:2.3:o:apple:mac_os_x_server:10.5.2:*:*:*:*:*:*:*
cpe:2.3:a:mit:kerberos_5:*:*:*:*:*:*:*:*

History

21 Nov 2024, 00:38

Type Values Removed Values Added
References () http://bugs.gentoo.org/show_bug.cgi?id=199214 - Exploit () http://bugs.gentoo.org/show_bug.cgi?id=199214 - Exploit
References () http://docs.info.apple.com/article.html?artnum=307562 - () http://docs.info.apple.com/article.html?artnum=307562 -
References () http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html - () http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html -
References () http://osvdb.org/43346 - () http://osvdb.org/43346 -
References () http://seclists.org/fulldisclosure/2007/Dec/0176.html - () http://seclists.org/fulldisclosure/2007/Dec/0176.html -
References () http://seclists.org/fulldisclosure/2007/Dec/0321.html - () http://seclists.org/fulldisclosure/2007/Dec/0321.html -
References () http://secunia.com/advisories/29451 - () http://secunia.com/advisories/29451 -
References () http://secunia.com/advisories/29464 - () http://secunia.com/advisories/29464 -
References () http://secunia.com/advisories/29516 - () http://secunia.com/advisories/29516 -
References () http://secunia.com/advisories/39290 - () http://secunia.com/advisories/39290 -
References () http://security.gentoo.org/glsa/glsa-200803-31.xml - () http://security.gentoo.org/glsa/glsa-200803-31.xml -
References () http://ubuntu.com/usn/usn-924-1 - () http://ubuntu.com/usn/usn-924-1 -
References () http://www.mandriva.com/security/advisories?name=MDVSA-2008:069 - () http://www.mandriva.com/security/advisories?name=MDVSA-2008:069 -
References () http://www.redhat.com/support/errata/RHSA-2008-0164.html - () http://www.redhat.com/support/errata/RHSA-2008-0164.html -
References () http://www.securityfocus.com/bid/26750 - Patch () http://www.securityfocus.com/bid/26750 - Patch
References () http://www.vupen.com/english/advisories/2008/0924/references - () http://www.vupen.com/english/advisories/2008/0924/references -
References () https://issues.rpath.com/browse/RPL-2012 - () https://issues.rpath.com/browse/RPL-2012 -
References () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11451 - () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11451 -
References () https://www.redhat.com/archives/fedora-package-announce/2008-March/msg00537.html - () https://www.redhat.com/archives/fedora-package-announce/2008-March/msg00537.html -
References () https://www.redhat.com/archives/fedora-package-announce/2008-March/msg00544.html - () https://www.redhat.com/archives/fedora-package-announce/2008-March/msg00544.html -

Information

Published : 2007-12-06 02:46

Updated : 2024-11-21 00:38


NVD link : CVE-2007-5901

Mitre link : CVE-2007-5901

CVE.ORG link : CVE-2007-5901


JSON object : View

Products Affected

apple

  • mac_os_x
  • mac_os_x_server

mit

  • kerberos_5
CWE
CWE-399

Resource Management Errors