CVE-2007-3999
librpcsecgss - arbitrary code execution
EPSS 11.0%
描述
Stack-based buffer overflow in the svcauth_gss_validate function in lib/rpc/svc_auth_gss.c in the RPCSEC_GSS RPC library (librpcsecgss) in MIT Kerberos 5 (krb5) 1.4 through 1.6.2, as used by the Kerberos administration daemon (kadmind) and some third-party applications that use krb5, allows remote attackers to cause a denial of service (daemon crash) and probably execute arbitrary code via a long string in an RPC message.
如何修補 CVE-2007-3999
要修補 CVE-2007-3999,請將受影響套件升級到下列已修補版本。
- Debian/krb5—升級至 1.6.dfsg.1-7 或更新版本
- —升級至 1.4.4-7etch4 或更新版本
- —升級至 0.14-2etch1 或更新版本
CVE-2007-3999 正在被利用嗎?
中等 — EPSS 為 11.0%,可持續追蹤但非最高優先。
受影響套件(3)
- from 0, < 1.6.dfsg.1-7
- from 0, < 1.4.4-7etch4
- from 0, < 0.14-2etch1