---
title: "CVE-2007-4000\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2007-4000?format=md
keywords: index, follow
---

# CVE-2007-4000

Publication date 5 September 2007

Last updated 17 July 2025

---

Ubuntu priority

**Medium**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

Toggle side navigation

## Description

The kadm5\_modify\_policy\_internal function in lib/kadm5/srv/svr\_policy.c in
the Kerberos administration daemon (kadmind) in MIT Kerberos 5 (krb5) 1.5
through 1.6.2 does not properly check return values when the policy does
not exist, which might allow remote authenticated users with the "modify
policy" privilege to execute arbitrary code via unspecified vectors that
trigger a write to an uninitialized pointer.

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| krb5 | 7.04 feisty | Not affected |
| 6.10 edgy | Not affected |
| 6.06 LTS dapper | Not affected |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4000)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2007-4000)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2007-4000)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2007-4000)

### Other references

* <https://www.cve.org/CVERecord?id=CVE-2007-4000>
