Your submission was sent successfully! Close

CVE-2007-1216

Published: 6 April 2007

Double free vulnerability in the GSS-API library (lib/gssapi/krb5/k5unseal.c), as used by the Kerberos administration daemon (kadmind) in MIT krb5 before 1.6.1, when used with the authentication method provided by the RPCSEC_GSS RPC library, allows remote authenticated users to execute arbitrary code and modify the Kerberos key database via a message with an "an invalid direction encoding".

Priority

Unknown

Status

Package Release Status
krb5
Launchpad, Ubuntu, Debian
dapper
Released (1.4.3-5ubuntu0.6)
edgy
Released (1.4.3-9ubuntu1.5)
feisty
Released (1.4.4-5ubuntu3.3)
upstream Needs triage