CVE-2006-6143
Summary
| CVE | CVE-2006-6143 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2006-12-31 05:00:00 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | The RPC library in Kerberos 5 1.4 through 1.4.4, and 1.5 through 1.5.1, as used in Kerberos administration daemon (kadmind) and other products that use this library, calls an uninitialized function pointer in freed memory, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unspecified vectors. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:N/AC:M/Au:N/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Canonical | Ubuntu Linux | 6.06 | All | All | All |
| Operating System | Canonical | Ubuntu Linux | 6.10 | All | All | All |
| Application | Mit | Kerberos 5 | 1.4 | All | All | All |
| Application | Mit | Kerberos 5 | 1.4.1 | All | All | All |
| Application | Mit | Kerberos 5 | 1.4.2 | All | All | All |
| Application | Mit | Kerberos 5 | 1.4.3 | All | All | All |
| Application | Mit | Kerberos 5 | 1.4.4 | All | All | All |
| Application | Mit | Kerberos 5 | 1.5 | All | All | All |
| Application | Mit | Kerberos 5 | 1.5.1 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| SUSE update for Kerberos - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Broken Link |
| About Security Update 2007-004 | af854a3a-2127-422b-91ae-364da2661108 | docs.info.apple.com | Broken Link |
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Broken Link, Third Party Advisory, VDB Entry |
| US-CERT Vulnerability Note VU#481564 | af854a3a-2127-422b-91ae-364da2661108 | www.kb.cert.org | Patch, Third Party Advisory, US Government Resource |
| US-CERT Technical Cyber Security Alert TA07-009B -- MIT Kerberos Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.us-cert.gov | Broken Link, Patch, Third Party Advisory, US Government Resource |
| Fedora Core 6 update for krb5 - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Broken Link |
| USN-408-1: krb5 vulnerability | Ubuntu | af854a3a-2127-422b-91ae-364da2661108 | www.ubuntu.com | Third Party Advisory |
| OpenPKG Corporation: Security: Security Advisories | af854a3a-2127-422b-91ae-364da2661108 | www.openpkg.com | Broken Link |
| APPLE-SA-2007-04-19 Security Update 2007-004 | af854a3a-2127-422b-91ae-364da2661108 | lists.apple.com | Mailing List |
| Mandriva update for krb5 - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Broken Link |
| Kerberos kadmind xprt->xp_auth Code Execution Vulnerability - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Broken Link |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | Third Party Advisory, VDB Entry |
| MIT Kerberos 5 RPC Library Remote Code Execution Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Broken Link, Third Party Advisory, VDB Entry |
| issues.rpath.com/browse/RPL-925 | af854a3a-2127-422b-91ae-364da2661108 | issues.rpath.com | Broken Link |
| Webmail - OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Broken Link |
| Gentoo Linux Documentation -- MIT Kerberos 5: Arbitrary Remote Code Execution | af854a3a-2127-422b-91ae-364da2661108 | security.gentoo.org | Third Party Advisory |
| [SECURITY] Fedora Core 6 Update: krb5-1.5-13 | FedoraNEWS.ORG | af854a3a-2127-422b-91ae-364da2661108 | fedoranews.org | Broken Link |
| Ubuntu update for krb5 - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Broken Link |
| SuSE Security announcements: [suse-security-announce] SUSE Security Announcement: krb5 security problems (SUSE-SA:2007:004) | af854a3a-2127-422b-91ae-364da2661108 | lists.suse.com | Broken Link |
| Advisories | Mandriva | af854a3a-2127-422b-91ae-364da2661108 | www.mandriva.com | Third Party Advisory |
| Webmail - OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Broken Link |
| osvdb.org/31281 | af854a3a-2127-422b-91ae-364da2661108 | osvdb.org | Broken Link |
| Gentoo update for mit-krb5 - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Broken Link |
| web.mit.edu/kerberos/www/advisories/MITKRB5-SA-2006-002-rpc.txt | af854a3a-2127-422b-91ae-364da2661108 | web.mit.edu | Patch, Vendor Advisory |
| Kerberos kadmind SVCAUTH_DESTROY() Lets Remote Users Execute Arbitrary Code - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | securitytracker.com | Broken Link, Third Party Advisory, VDB Entry |
| Fedora Core 5 update for krb5 - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Broken Link |
| US-CERT Technical Cyber Security Alert TA07-109A -- Apple Updates for Multiple Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.us-cert.gov | Broken Link, Third Party Advisory, US Government Resource |
| 404 Not Found | af854a3a-2127-422b-91ae-364da2661108 | fedoranews.org | Broken Link |
| Mac OS X Security Update Fixes Multiple Vulnerabilities - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Broken Link |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
| Organization | Published | Contributor | Statement |
|---|---|---|---|
| Red Hat | 2007-03-14 | Mark J Cox | Not vulnerable. Red Hat Enterprise Linux 2.1, 3, and 4 ship with versions of Kerberos 5 prior to version 1.4 and are therefore not affected by these vulnerabilities. Red Hat Enterprise Linux 5 is not vulnerable to this issue as it contains a backported patch. |
There are currently no legacy QID mappings associated with this CVE.