Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 161260 - mit-krb5: kadmind (via GSS-API mechglue) frees uninitialized pointers
Summary: mit-krb5: kadmind (via GSS-API mechglue) frees uninitialized pointers
Status: RESOLVED DUPLICATE of bug 158810
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High critical (vote)
Assignee: Gentoo Security
URL: http://web.mit.edu/kerberos/www/advis...
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2007-01-10 02:34 UTC by Paul B. Henson
Modified: 2007-01-10 14:51 UTC (History)
0 users

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Paul B. Henson 2007-01-10 02:34:17 UTC
MIT krb5 Security Advisory 2006-003

Original release: 2007-01-09
Last update: 2007-01-09

Topic: kadmind (via GSS-API mechglue) frees uninitialized pointers

Severity: CRITICAL

CVE: CVE-2006-6144
CERT: VU#831452

SUMMARY
=======

The Kerberos administration daemon, "kadmind", can free uninitialized
pointers, possibly leading to arbitrary code execution.  This
vulnerability results from memory management bugs in the "mechglue"
abstraction interface of the GSS-API implementation.  Third-party
applications written using the GSS-API may also be vulnerable.

Exploitation of this vulnerability is believed to be difficult.  No
exploit code is known to exist at this time.


Reproducible: Always
Comment 1 Seemant Kulleen (RETIRED) gentoo-dev 2007-01-10 14:51:11 UTC

*** This bug has been marked as a duplicate of bug 158810 ***