The RPC library in Kerberos 5 1.4 through 1.4.4, and 1.5 through 1.5.1, as used in Kerberos administration daemon (kadmind) and other products that use this library, calls an uninitialized function pointer in freed memory, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unspecified vectors.
References
Link Resource
http://docs.info.apple.com/article.html?artnum=305391 Broken Link
http://fedoranews.org/cms/node/2375 Broken Link
http://fedoranews.org/cms/node/2376 Broken Link
http://lists.apple.com/archives/Security-announce/2007/Apr/msg00001.html Mailing List
http://lists.suse.com/archive/suse-security-announce/2007-Jan/0004.html Broken Link
http://osvdb.org/31281 Broken Link
http://secunia.com/advisories/23667 Broken Link
http://secunia.com/advisories/23696 Broken Link
http://secunia.com/advisories/23701 Broken Link
http://secunia.com/advisories/23706 Broken Link
http://secunia.com/advisories/23707 Broken Link
http://secunia.com/advisories/23772 Broken Link
http://secunia.com/advisories/23903 Broken Link
http://secunia.com/advisories/24966 Broken Link
http://security.gentoo.org/glsa/glsa-200701-21.xml Third Party Advisory
http://securitytracker.com/id?1017493 Broken Link Third Party Advisory VDB Entry
http://web.mit.edu/kerberos/www/advisories/MITKRB5-SA-2006-002-rpc.txt Patch Vendor Advisory
http://www.kb.cert.org/vuls/id/481564 Patch Third Party Advisory US Government Resource
http://www.mandriva.com/security/advisories?name=MDKSA-2007:008 Third Party Advisory
http://www.openpkg.com/security/advisories/OpenPKG-SA-2007.006.html Broken Link
http://www.securityfocus.com/archive/1/456406/100/0/threaded Broken Link Third Party Advisory VDB Entry
http://www.securityfocus.com/bid/21970 Broken Link Third Party Advisory VDB Entry
http://www.ubuntu.com/usn/usn-408-1 Third Party Advisory
http://www.us-cert.gov/cas/techalerts/TA07-009B.html Broken Link Patch Third Party Advisory US Government Resource
http://www.us-cert.gov/cas/techalerts/TA07-109A.html Broken Link Third Party Advisory US Government Resource
http://www.vupen.com/english/advisories/2007/0111 Broken Link
http://www.vupen.com/english/advisories/2007/1470 Broken Link
https://exchange.xforce.ibmcloud.com/vulnerabilities/31422 Third Party Advisory VDB Entry
https://issues.rpath.com/browse/RPL-925 Broken Link
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2007-01-10T00:00:00

Updated: 2018-10-17T20:57:01

Reserved: 2006-11-28T00:00:00


Link: CVE-2006-6143

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2006-12-31T05:00:00.000

Modified: 2024-02-09T03:26:18.233


Link: CVE-2006-6143

JSON object: View

cve-icon Redhat Information

No data.

CWE