CVE-2007-3999

N/A Unknown
Published: September 05, 2007 Modified: April 23, 2026
View on NVD

Description

Stack-based buffer overflow in the svcauth_gss_validate function in lib/rpc/svc_auth_gss.c in the RPCSEC_GSS RPC library (librpcsecgss) in MIT Kerberos 5 (krb5) 1.4 through 1.6.2, as used by the Kerberos administration daemon (kadmind) and some third-party applications that use krb5, allows remote attackers to cause a denial of service (daemon crash) and probably execute arbitrary code via a long string in an RPC message.

AI Explanation

Get an AI-powered plain-language explanation of this vulnerability and remediation steps.

Login to generate AI explanation

References to Advisories, Solutions, and Tools

Patch Vendor Advisory Exploit Third Party Advisory
http://secunia.com/advisories/26676
Source: cve@mitre.org
Vendor Advisory
http://secunia.com/advisories/26680
Source: cve@mitre.org
Vendor Advisory
http://secunia.com/advisories/26684
Source: cve@mitre.org
Vendor Advisory
http://secunia.com/advisories/26691
Source: cve@mitre.org
Vendor Advisory
http://secunia.com/advisories/26697
Source: cve@mitre.org
Vendor Advisory
http://secunia.com/advisories/26699
Source: cve@mitre.org
Vendor Advisory
http://secunia.com/advisories/26700
Source: cve@mitre.org
Vendor Advisory
http://secunia.com/advisories/26705
Source: cve@mitre.org
Vendor Advisory
http://secunia.com/advisories/26713
Source: cve@mitre.org
Vendor Advisory
http://secunia.com/advisories/26728
Source: cve@mitre.org
Vendor Advisory
http://secunia.com/advisories/26783
Source: cve@mitre.org
Vendor Advisory
http://secunia.com/advisories/26792
Source: cve@mitre.org
Vendor Advisory
http://secunia.com/advisories/26822
Source: cve@mitre.org
Vendor Advisory
http://secunia.com/advisories/26896
Source: cve@mitre.org
Vendor Advisory
http://secunia.com/advisories/26987
Source: cve@mitre.org
Vendor Advisory
http://secunia.com/advisories/27043
Source: cve@mitre.org
Vendor Advisory
http://secunia.com/advisories/27081
Source: cve@mitre.org
Vendor Advisory
http://secunia.com/advisories/27146
Source: cve@mitre.org
Vendor Advisory
http://secunia.com/advisories/27643
Source: cve@mitre.org
Vendor Advisory
http://www.kb.cert.org/vuls/id/883632
Source: cve@mitre.org
US Government Resource
http://www.us-cert.gov/cas/techalerts/TA07-319A.html
Source: cve@mitre.org
US Government Resource
http://docs.info.apple.com/article.html?artnum=307041
Source: af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/26676
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
http://secunia.com/advisories/26680
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
http://secunia.com/advisories/26684
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
http://secunia.com/advisories/26691
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
http://secunia.com/advisories/26697
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
http://secunia.com/advisories/26699
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
http://secunia.com/advisories/26700
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
http://secunia.com/advisories/26705
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
http://secunia.com/advisories/26713
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
http://secunia.com/advisories/26728
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
http://secunia.com/advisories/26783
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
http://secunia.com/advisories/26792
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
http://secunia.com/advisories/26822
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
http://secunia.com/advisories/26896
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
http://secunia.com/advisories/26987
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
http://secunia.com/advisories/27043
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
http://secunia.com/advisories/27081
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
http://secunia.com/advisories/27146
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
http://secunia.com/advisories/27643
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
http://secunia.com/advisories/27756
Source: af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/29247
Source: af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/29270
Source: af854a3a-2127-422b-91ae-364da2661108
http://security.gentoo.org/glsa/glsa-200710-01.xml
Source: af854a3a-2127-422b-91ae-364da2661108
http://securityreason.com/securityalert/3092
Source: af854a3a-2127-422b-91ae-364da2661108
http://sunsolve.sun.com/search/document.do?assetkey=1-26-103060-1
Source: af854a3a-2127-422b-91ae-364da2661108
http://sunsolve.sun.com/search/document.do?assetkey=1-66-201319-1
Source: af854a3a-2127-422b-91ae-364da2661108
http://support.avaya.com/elmodocs2/security/ASA-2007-396.htm
Source: af854a3a-2127-422b-91ae-364da2661108
http://web.mit.edu/Kerberos/advisories/MITKRB5-SA-2007-006.txt
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.debian.org/security/2007/dsa-1367
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.debian.org/security/2007/dsa-1368
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.gentoo.org/security/en/glsa/glsa-200709-01.xml
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.kb.cert.org/vuls/id/883632
Source: af854a3a-2127-422b-91ae-364da2661108
US Government Resource
http://www.mandriva.com/security/advisories?name=MDKSA-2007:174
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.mandriva.com/security/advisories?name=MDKSA-2007:181
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.novell.com/linux/security/advisories/2007_19_sr.html
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.novell.com/linux/security/advisories/2007_24_sr.html
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.redhat.com/support/errata/RHSA-2007-0858.html
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.redhat.com/support/errata/RHSA-2007-0913.html
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.redhat.com/support/errata/RHSA-2007-0951.html
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.securityfocus.com/archive/1/478748/100/0/threaded
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.securityfocus.com/archive/1/479251/100/0/threaded
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.securityfocus.com/bid/25534
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.securityfocus.com/bid/26444
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.securitytracker.com/id?1018647
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.trustix.org/errata/2007/0026/
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.ubuntu.com/usn/usn-511-1
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.us-cert.gov/cas/techalerts/TA07-319A.html
Source: af854a3a-2127-422b-91ae-364da2661108
US Government Resource
http://www.vupen.com/english/advisories/2007/3051
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.vupen.com/english/advisories/2007/3052
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.vupen.com/english/advisories/2007/3060
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.vupen.com/english/advisories/2007/3868
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.vupen.com/english/advisories/2008/0803/references
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.zerodayinitiative.com/advisories/ZDI-07-052.html
Source: af854a3a-2127-422b-91ae-364da2661108
https://bugzilla.redhat.com/show_bug.cgi?id=250973
Source: af854a3a-2127-422b-91ae-364da2661108
https://exchange.xforce.ibmcloud.com/vulnerabilities/36437
Source: af854a3a-2127-422b-91ae-364da2661108

124 reference(s) from NVD

Quick Stats

CVSS v3 Score
N/A / 10.0
EPSS (Exploit Probability)
10.9%
95th percentile
Exploitation Status
Not in CISA KEV

Weaknesses (CWE)

Affected Vendors

mit