CVE-2007-5902
EPSS 5.9%
Description
Integer overflow in the svcauth_gss_get_principal function in lib/rpc/svc_auth_gss.c in MIT Kerberos 5 (krb5) allows remote attackers to have an unknown impact via a large length value for a GSS client name in an RPC request.
How to fix CVE-2007-5902
To remediate CVE-2007-5902, upgrade the affected package to a fixed version below.
- Debian/krb5—upgrade to 1.6.dfsg.4~beta1-1 or later
Is CVE-2007-5902 being exploited?
Moderate — EPSS is 5.9%. Track this CVE but it's not at the top of the prioritisation list.
Affected packages (1)
- from 0, < 1.6.dfsg.4~beta1-1