CVE-2007-4000
Last modified
CVE-2007-4000 is a vulnerability of currently unknown severity. The kadm5_modify_policy_internal function in lib/kadm5/srv/svr_policy.c in the Kerberos administration daemon (kadmind) in MIT Kerberos 5 (krb5) 1.5 through 1.6.2 does not properly check return values when the policy does not exist, which might allow remote authenticated users with the "modify policy" privilege to execute arbitrary code via unspecified vectors that trigger a write to an uninitialized pointer.. EPSS estimates a 6.14% chance of exploitation in the next 30 days.
Description
The kadm5_modify_policy_internal function in lib/kadm5/srv/svr_policy.c in the Kerberos administration daemon (kadmind) in MIT Kerberos 5 (krb5) 1.5 through 1.6.2 does not properly check return values when the policy does not exist, which might allow remote authenticated users with the "modify policy" privilege to execute arbitrary code via unspecified vectors that trigger a write to an uninitialized pointer.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Mit | Kerberos 5 | >= 1.5, <= 1.6.2 |
| Fedoraproject | Fedora | 7 |
References
- http://secunia.com/advisories/26676Broken Link
- http://secunia.com/advisories/26680Broken Link
- http://secunia.com/advisories/26700Broken Link
- http://secunia.com/advisories/26728Broken Link
- http://secunia.com/advisories/26783Broken Link
- http://secunia.com/advisories/26987Broken Link
- http://securityreason.com/securityalert/3092Broken Link
- http://www.gentoo.org/security/en/glsa/glsa-200709-01.xmlThird Party Advisory
- http://www.kb.cert.org/vuls/id/377544Third Party Advisory, US Government Resource
- http://www.redhat.com/support/errata/RHSA-2007-0858.htmlThird Party Advisory
- http://www.securityfocus.com/archive/1/478794/100/0/threadedThird Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/25533Broken Link, Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id?1018647Broken Link, Third Party Advisory, VDB Entry
- https://bugzilla.redhat.com/show_bug.cgi?id=250976Issue Tracking
- https://exchange.xforce.ibmcloud.com/vulnerabilities/36438Broken Link, VDB Entry
- https://issues.rpath.com/browse/RPL-1696Broken Link
- http://secunia.com/advisories/26676Broken Link
- http://secunia.com/advisories/26680Broken Link
- http://secunia.com/advisories/26700Broken Link
- http://secunia.com/advisories/26728Broken Link
- http://secunia.com/advisories/26783Broken Link
- http://secunia.com/advisories/26987Broken Link
- http://securityreason.com/securityalert/3092Broken Link
- http://www.gentoo.org/security/en/glsa/glsa-200709-01.xmlThird Party Advisory
- http://www.kb.cert.org/vuls/id/377544Third Party Advisory, US Government Resource
- http://www.redhat.com/support/errata/RHSA-2007-0858.htmlThird Party Advisory
- http://www.securityfocus.com/archive/1/478794/100/0/threadedThird Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/25533Broken Link, Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id?1018647Broken Link, Third Party Advisory, VDB Entry
- https://bugzilla.redhat.com/show_bug.cgi?id=250976Issue Tracking
- https://exchange.xforce.ibmcloud.com/vulnerabilities/36438Broken Link, VDB Entry
- https://issues.rpath.com/browse/RPL-1696Broken Link
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2007-4000?
How severe is CVE-2007-4000?
How do I fix CVE-2007-4000?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2007
- CVE-2007-3992SQL injection vulnerability in vir_login.asp in iExpress Pro…
- CVE-2007-3993Unspecified vulnerability in the attachment filter in Kerio …
- CVE-2007-3996Multiple integer overflows in libgd in PHP before 5.2.4 allo…
- CVE-2007-3997The (1) MySQL and (2) MySQLi extensions in PHP 4 before 4.4.…
- CVE-2007-3998The wordwrap function in PHP 4 before 4.4.8, and PHP 5 befor…
- CVE-2007-3999Stack-based buffer overflow in the svcauth_gss_validate func…
- CVE-2007-4003pioout in IBM AIX 5.3 SP6 allows local users to execute arbi…
- CVE-2007-4004Buffer overflow in the ftp client in IBM AIX 5.3 SP6 and 5.2…
- CVE-2007-4005Stack-based buffer overflow in Mike Dubman Windows RSH daemo…
- CVE-2007-4006Buffer overflow in Mike Dubman Windows RSH daemon (rshd) 1.7…
- CVE-2007-4007PHP remote file inclusion vulnerability in index.php in Arti…
- CVE-2007-4008Directory traversal vulnerability in custom.php in Entertain…
Are you affected by CVE-2007-4000?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
