CVE-2006-6143
The RPC library in Kerberos 5 1.4 through 1.4.4, and 1.5 through 1.5.1, as used in Kerberos administration daemon (kadmind) and other products that use this library, calls an uninitialized function pointer in freed memory, which allows remote attackers…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (7.92%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The RPC library in Kerberos 5 1.4 through 1.4.4, and 1.5 through 1.5.1, as used in Kerberos administration daemon (kadmind) and other products that use this library, calls an uninitialized function pointer in freed memory, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unspecified vectors.
- CVSS 2.0
- 9.3 HIGHAV:N/AC:M/Au:N/C:C/I:C/A:C
- EPSS
- 7.92% probability · 94th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-824
- Affected
- mit/kerberos 5 · canonical/ubuntu linux
- Source
- cve@mitre.org
References
- http://docs.info.apple.com/article.html?artnum=305391Broken Link
- http://fedoranews.org/cms/node/2375Broken Link
- http://fedoranews.org/cms/node/2376Broken Link
- http://lists.apple.com/archives/Security-announce/2007/Apr/msg00001.htmlMailing List
- http://lists.suse.com/archive/suse-security-announce/2007-Jan/0004.htmlBroken Link
- http://osvdb.org/31281Broken Link
- http://secunia.com/advisories/23667Broken Link
- http://secunia.com/advisories/23696Broken Link
- http://secunia.com/advisories/23701Broken Link
- http://secunia.com/advisories/23706Broken Link
- http://secunia.com/advisories/23707Broken Link
- http://secunia.com/advisories/23772Broken Link
- http://secunia.com/advisories/23903Broken Link
- http://secunia.com/advisories/24966Broken Link
- http://security.gentoo.org/glsa/glsa-200701-21.xmlThird Party Advisory
- http://securitytracker.com/id?1017493Broken Link, Third Party Advisory, VDB Entry
- http://web.mit.edu/kerberos/www/advisories/MITKRB5-SA-2006-002-rpc.txtPatch, Vendor Advisory
- http://www.kb.cert.org/vuls/id/481564Patch, Third Party Advisory, US Government Resource
- http://www.mandriva.com/security/advisories?name=MDKSA-2007:008Third Party Advisory
- http://www.openpkg.com/security/advisories/OpenPKG-SA-2007.006.htmlBroken Link
- http://www.securityfocus.com/archive/1/456406/100/0/threadedBroken Link, Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/21970Broken Link, Third Party Advisory, VDB Entry
- http://www.ubuntu.com/usn/usn-408-1Third Party Advisory
- http://www.us-cert.gov/cas/techalerts/TA07-009B.htmlBroken Link, Patch, Third Party Advisory, US Government Resource
- http://www.us-cert.gov/cas/techalerts/TA07-109A.htmlBroken Link, Third Party Advisory, US Government Resource
- http://www.vupen.com/english/advisories/2007/0111Broken Link
- http://www.vupen.com/english/advisories/2007/1470Broken Link
- https://exchange.xforce.ibmcloud.com/vulnerabilities/31422Third Party Advisory, VDB Entry
- https://issues.rpath.com/browse/RPL-925Broken Link
- http://docs.info.apple.com/article.html?artnum=305391Broken Link
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.