CVE: CVE-2007-2442

Export to Word

The gssrpc__svcauth_gssapi function in the RPC library in MIT Kerberos 5 (krb5) 1.6.1 and earlier might allow remote attackers to execute arbitrary code via a zero-length RPC credential, which causes kadmind to free an uninitialized pointer during cleanup.

Threat-Mapped Scoring

Score: 1.8

Priority: P4 - Informational (Low)

EPSS

Score: 0.39316
Percentile: 0.97132

CVSS Scoring

CVSS v2 Score: 10.0

Severity:

Mapped CWE(s)

Affected Products

← Back to Home