Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2007-4000
Description:The kadm5_modify_policy_internal function in lib/kadm5/srv/svr_policy.c in the Kerberos administration daemon (kadmind) in MIT Kerberos 5 (krb5) 1.5 through 1.6.2 does not properly check return values when the policy does not exist, which might allow remote authenticated users with the "modify policy" privilege to execute arbitrary code via unspecified vectors that trigger a write to an uninitialized pointer.
Test IDs: None available
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2007-4000
BugTraq ID: 25533
http://www.securityfocus.com/bid/25533
Bugtraq: 20070907 FLEA-2007-0050-1 krb5 krb5-workstation (Google Search)
http://www.securityfocus.com/archive/1/478794/100/0/threaded
CERT/CC vulnerability note: VU#377544
http://www.kb.cert.org/vuls/id/377544
https://www.redhat.com/archives/fedora-package-announce/2007-September/msg00087.html
http://www.gentoo.org/security/en/glsa/glsa-200709-01.xml
http://www.mandriva.com/security/advisories?name=MDKSA-2007:174
https://bugzilla.redhat.com/show_bug.cgi?id=250976
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9278
RedHat Security Advisories: RHSA-2007:0858
http://www.redhat.com/support/errata/RHSA-2007-0858.html
http://www.securitytracker.com/id?1018647
http://secunia.com/advisories/26676
http://secunia.com/advisories/26680
http://secunia.com/advisories/26700
http://secunia.com/advisories/26728
http://secunia.com/advisories/26783
http://secunia.com/advisories/26987
http://securityreason.com/securityalert/3092
SuSE Security Announcement: SUSE-SR:2007:019 (Google Search)
http://www.novell.com/linux/security/advisories/2007_19_sr.html
http://www.vupen.com/english/advisories/2007/3051
XForce ISS Database: kerberos-modifypolicy-code-execution(36438)
https://exchange.xforce.ibmcloud.com/vulnerabilities/36438




© 1998-2025 E-Soft Inc. All rights reserved.