Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.59938
Category:Mandrake Local Security Checks
Title:Mandrake Security Advisory MDKSA-2007:239 (heimdal)
Summary:NOSUMMARY
Description:Description:

The remote host is missing an update to heimdal
announced via advisory MDKSA-2007:239.

It was found that the gss_userok() function in Heimdal 0.7.2 did not
allocate memory for the ticketfile pointer before calling free(), which
could possibly allow remote attackers to have an unknown impact via an
invalid username. It is uncertain whether or not this is exploitable,
however packages are being provided regardless.

The updated packages have been patched to correct these issues.

Affected: Corporate 4.0

Solution:
To upgrade automatically use MandrakeUpdate or urpmi. The verification
of md5 checksums and GPG signatures is performed automatically for you.

http://www.securityspace.com/smysecure/catid.html?in=MDKSA-2007:239

Risk factor : Critical

CVSS Score:
10.0

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2007-5939
BugTraq ID: 26758
http://www.securityfocus.com/bid/26758
http://marc.info/?l=full-disclosure&m=119704362903699&w=2
http://www.mandriva.com/security/advisories?name=MDKSA-2007:239
http://osvdb.org/44750
http://securitytracker.com/id?1019057
CopyrightCopyright (c) 2007 E-Soft Inc. http://www.securityspace.com

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.