CVE-2007-2442

CVE-2007-2442

CVE-2007-2442 · HIGH Severity

AV:N/AC:L/AU:N/C:C/I:C/A:C

The gssrpc__svcauth_gssapi function in the RPC library in MIT Kerberos 5 (krb5) 1.6.1 and earlier might allow remote attackers to execute arbitrary code via a zero-length RPC credential, which causes kadmind to free an uninitialized pointer during cleanup.

Learn more about our Cis Benchmark Audit For Mit Kerberos.