CVE-2007-4743
Summary
| CVE | CVE-2007-4743 |
|---|---|
| State | PUBLISHED |
| Assigner | redhat |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2007-09-06 22:17:00 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | The original patch for CVE-2007-3999 in svc_auth_gss.c in the RPCSEC_GSS RPC library in MIT Kerberos 5 (krb5) 1.4 through 1.6.2, as used by the Kerberos administration daemon (kadmind) and other applications that use krb5, does not correctly check the buffer length in some environments and architectures, which might allow remote attackers to conduct a buffer overflow attack. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:N/AC:L/Au:N/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Mit | Kerberos 5 | 1.4 | All | All | All |
| Application | Mit | Kerberos 5 | 1.4.1 | All | All | All |
| Application | Mit | Kerberos 5 | 1.4.2 | All | All | All |
| Application | Mit | Kerberos 5 | 1.4.3 | All | All | All |
| Application | Mit | Kerberos 5 | 1.4.4 | All | All | All |
| Application | Mit | Kerberos 5 | 1.5 | All | All | All |
| Application | Mit | Kerberos 5 | 1.5.1 | All | All | All |
| Application | Mit | Kerberos 5 | 1.5.2 | All | All | All |
| Application | Mit | Kerberos 5 | 1.5.3 | All | All | All |
| Application | Mit | Kerberos 5 | 1.6 | All | All | All |
| Application | Mit | Kerberos 5 | 1.6.1 | All | All | All |
| Application | Mit | Kerberos 5 | 1.6.2 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | |
| rPath update for krb5 - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Security Announcement | af854a3a-2127-422b-91ae-364da2661108 | www.novell.com | |
| About the security content of Mac OS X 10.4.11 and Security Update 2007-008 | af854a3a-2127-422b-91ae-364da2661108 | docs.info.apple.com | |
| Support | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | |
| US-CERT Technical Cyber Security Alert TA07-319A -- Apple Updates for Multiple Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.us-cert.gov | US Government Resource |
| Apple Mac OS X Security Update Fixes Multiple Vulnerabilities - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| [#RPL-1696] RPL:1 krb5 multiple issues CVE-2007-3999 CVE-2007-4743 - rPath Issue Tracking System | af854a3a-2127-422b-91ae-364da2661108 | issues.rpath.com | |
| Apple Mac OS X v10.4.11 2007-008 Multiple Security Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| USN-511-2: Kerberos vulnerability | Ubuntu | af854a3a-2127-422b-91ae-364da2661108 | www.ubuntu.com | |
| APPLE-SA-2007-11-14 Mac OS X v10.4.11 and Security Update 2007-008 | af854a3a-2127-422b-91ae-364da2661108 | lists.apple.com | |
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| SUSE Update for Multiple Packages - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Gmane -- Mail To News And Back Again | af854a3a-2127-422b-91ae-364da2661108 | article.gmane.org | Patch |
| Debian -- Security Information -- DSA-1387-1 librpcsecgss | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | |
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.