mit kerberos-5 CVE-2007-5894 is a vulnerability in MIT Kerberos 5
Published on December 6, 2007

The reply function in ftpd.c in the gssftp ftpd in MIT Kerberos 5 (krb5) does not initialize the length variable when auth_type has a certain value, which has unknown impact and remote authenticated attack vectors. NOTE: the original disclosure misidentifies the conditions under which the uninitialized variable is used. NOTE: the vendor disputes this issue, stating " The 'length' variable is only uninitialized if 'auth_type' is neither the 'KERBEROS_V4' nor 'GSSAPI'; this condition cannot occur in the unmodified source code.

Vendor Advisory NVD


Products Associated with CVE-2007-5894

Want to know whenever a new CVE is published for MIT Kerberos 5? stack.watch will email you.

 

Exploit Probability

EPSS
2.77%
Percentile
85.80%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.