CVE-2007-5902
EPSS 4.0%
Description
Integer overflow in the svcauth_gss_get_principal function in lib/rpc/svc_auth_gss.c in MIT Kerberos 5 (krb5) allows remote attackers to have an unknown impact via a large length value for a GSS client name in an RPC request.
How to fix CVE-2007-5902
To remediate CVE-2007-5902, upgrade the affected package to a fixed version below.
- Debian/krb5—upgrade to 1.6.dfsg.4~beta1-1 or later
Is CVE-2007-5902 being exploited?
Low — EPSS is 4.0%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 1.6.dfsg.4~beta1-1