CVE-2007-5971

Double free vulnerability in the gss_krb5int_make_seal_token_v3 function in lib/gssapi/krb5/k5sealv3.c in MIT Kerberos 5 (krb5) has unknown impact and attack vectors.
References
Link Resource
http://bugs.gentoo.org/show_bug.cgi?id=199212
http://docs.info.apple.com/article.html?artnum=307562
http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html
http://osvdb.org/43345
http://seclists.org/fulldisclosure/2007/Dec/0176.html
http://seclists.org/fulldisclosure/2007/Dec/0321.html
http://secunia.com/advisories/28636 Vendor Advisory
http://secunia.com/advisories/29420
http://secunia.com/advisories/29450
http://secunia.com/advisories/29451
http://secunia.com/advisories/29457
http://secunia.com/advisories/29462
http://secunia.com/advisories/29464
http://secunia.com/advisories/29516
http://secunia.com/advisories/39290
http://secunia.com/advisories/39784
http://security.gentoo.org/glsa/glsa-200803-31.xml
http://ubuntu.com/usn/usn-924-1
http://wiki.rpath.com/Advisories:rPSA-2008-0112
http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0112
http://www.mandriva.com/security/advisories?name=MDVSA-2008:069
http://www.mandriva.com/security/advisories?name=MDVSA-2008:070
http://www.novell.com/linux/security/advisories/suse_security_summary_report.html
http://www.redhat.com/support/errata/RHSA-2008-0164.html
http://www.redhat.com/support/errata/RHSA-2008-0180.html
http://www.securityfocus.com/archive/1/489883/100/0/threaded
http://www.securityfocus.com/bid/26750 Patch
http://www.ubuntu.com/usn/USN-940-1
http://www.vupen.com/english/advisories/2008/0924/references
http://www.vupen.com/english/advisories/2010/1192
https://issues.rpath.com/browse/RPL-2012
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10296
https://www.redhat.com/archives/fedora-package-announce/2008-March/msg00537.html
https://www.redhat.com/archives/fedora-package-announce/2008-March/msg00544.html
http://bugs.gentoo.org/show_bug.cgi?id=199212
http://docs.info.apple.com/article.html?artnum=307562
http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html
http://osvdb.org/43345
http://seclists.org/fulldisclosure/2007/Dec/0176.html
http://seclists.org/fulldisclosure/2007/Dec/0321.html
http://secunia.com/advisories/28636 Vendor Advisory
http://secunia.com/advisories/29420
http://secunia.com/advisories/29450
http://secunia.com/advisories/29451
http://secunia.com/advisories/29457
http://secunia.com/advisories/29462
http://secunia.com/advisories/29464
http://secunia.com/advisories/29516
http://secunia.com/advisories/39290
http://secunia.com/advisories/39784
http://security.gentoo.org/glsa/glsa-200803-31.xml
http://ubuntu.com/usn/usn-924-1
http://wiki.rpath.com/Advisories:rPSA-2008-0112
http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0112
http://www.mandriva.com/security/advisories?name=MDVSA-2008:069
http://www.mandriva.com/security/advisories?name=MDVSA-2008:070
http://www.novell.com/linux/security/advisories/suse_security_summary_report.html
http://www.redhat.com/support/errata/RHSA-2008-0164.html
http://www.redhat.com/support/errata/RHSA-2008-0180.html
http://www.securityfocus.com/archive/1/489883/100/0/threaded
http://www.securityfocus.com/bid/26750 Patch
http://www.ubuntu.com/usn/USN-940-1
http://www.vupen.com/english/advisories/2008/0924/references
http://www.vupen.com/english/advisories/2010/1192
https://issues.rpath.com/browse/RPL-2012
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10296
https://www.redhat.com/archives/fedora-package-announce/2008-March/msg00537.html
https://www.redhat.com/archives/fedora-package-announce/2008-March/msg00544.html
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:o:apple:mac_os_x:10.4.11:*:*:*:*:*:*:*
cpe:2.3:o:apple:mac_os_x:10.5.2:*:*:*:*:*:*:*
cpe:2.3:o:apple:mac_os_x_server:10.4.11:*:*:*:*:*:*:*
cpe:2.3:o:apple:mac_os_x_server:10.5.2:*:*:*:*:*:*:*
cpe:2.3:a:mit:kerberos_5:*:*:*:*:*:*:*:*

History

21 Nov 2024, 00:39

Type Values Removed Values Added
References () http://bugs.gentoo.org/show_bug.cgi?id=199212 - () http://bugs.gentoo.org/show_bug.cgi?id=199212 -
References () http://docs.info.apple.com/article.html?artnum=307562 - () http://docs.info.apple.com/article.html?artnum=307562 -
References () http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html - () http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html -
References () http://osvdb.org/43345 - () http://osvdb.org/43345 -
References () http://seclists.org/fulldisclosure/2007/Dec/0176.html - () http://seclists.org/fulldisclosure/2007/Dec/0176.html -
References () http://seclists.org/fulldisclosure/2007/Dec/0321.html - () http://seclists.org/fulldisclosure/2007/Dec/0321.html -
References () http://secunia.com/advisories/28636 - Vendor Advisory () http://secunia.com/advisories/28636 - Vendor Advisory
References () http://secunia.com/advisories/29420 - () http://secunia.com/advisories/29420 -
References () http://secunia.com/advisories/29450 - () http://secunia.com/advisories/29450 -
References () http://secunia.com/advisories/29451 - () http://secunia.com/advisories/29451 -
References () http://secunia.com/advisories/29457 - () http://secunia.com/advisories/29457 -
References () http://secunia.com/advisories/29462 - () http://secunia.com/advisories/29462 -
References () http://secunia.com/advisories/29464 - () http://secunia.com/advisories/29464 -
References () http://secunia.com/advisories/29516 - () http://secunia.com/advisories/29516 -
References () http://secunia.com/advisories/39290 - () http://secunia.com/advisories/39290 -
References () http://secunia.com/advisories/39784 - () http://secunia.com/advisories/39784 -
References () http://security.gentoo.org/glsa/glsa-200803-31.xml - () http://security.gentoo.org/glsa/glsa-200803-31.xml -
References () http://ubuntu.com/usn/usn-924-1 - () http://ubuntu.com/usn/usn-924-1 -
References () http://wiki.rpath.com/Advisories:rPSA-2008-0112 - () http://wiki.rpath.com/Advisories:rPSA-2008-0112 -
References () http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0112 - () http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0112 -
References () http://www.mandriva.com/security/advisories?name=MDVSA-2008:069 - () http://www.mandriva.com/security/advisories?name=MDVSA-2008:069 -
References () http://www.mandriva.com/security/advisories?name=MDVSA-2008:070 - () http://www.mandriva.com/security/advisories?name=MDVSA-2008:070 -
References () http://www.novell.com/linux/security/advisories/suse_security_summary_report.html - () http://www.novell.com/linux/security/advisories/suse_security_summary_report.html -
References () http://www.redhat.com/support/errata/RHSA-2008-0164.html - () http://www.redhat.com/support/errata/RHSA-2008-0164.html -
References () http://www.redhat.com/support/errata/RHSA-2008-0180.html - () http://www.redhat.com/support/errata/RHSA-2008-0180.html -
References () http://www.securityfocus.com/archive/1/489883/100/0/threaded - () http://www.securityfocus.com/archive/1/489883/100/0/threaded -
References () http://www.securityfocus.com/bid/26750 - Patch () http://www.securityfocus.com/bid/26750 - Patch
References () http://www.ubuntu.com/usn/USN-940-1 - () http://www.ubuntu.com/usn/USN-940-1 -
References () http://www.vupen.com/english/advisories/2008/0924/references - () http://www.vupen.com/english/advisories/2008/0924/references -
References () http://www.vupen.com/english/advisories/2010/1192 - () http://www.vupen.com/english/advisories/2010/1192 -
References () https://issues.rpath.com/browse/RPL-2012 - () https://issues.rpath.com/browse/RPL-2012 -
References () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10296 - () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10296 -
References () https://www.redhat.com/archives/fedora-package-announce/2008-March/msg00537.html - () https://www.redhat.com/archives/fedora-package-announce/2008-March/msg00537.html -
References () https://www.redhat.com/archives/fedora-package-announce/2008-March/msg00544.html - () https://www.redhat.com/archives/fedora-package-announce/2008-March/msg00544.html -

Information

Published : 2007-12-06 02:46

Updated : 2024-11-21 00:39


NVD link : CVE-2007-5971

Mitre link : CVE-2007-5971

CVE.ORG link : CVE-2007-5971


JSON object : View

Products Affected

mit

  • kerberos_5

apple

  • mac_os_x
  • mac_os_x_server
CWE
CWE-399

Resource Management Errors