{"api_version":"1","generated_at":"2026-07-23T09:11:59+00:00","cve":"CVE-2007-4000","urls":{"html":"https://cve.report/CVE-2007-4000","api":"https://cve.report/api/cve/CVE-2007-4000.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2007-4000","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2007-4000"},"summary":{"title":"CVE-2007-4000","description":"The kadm5_modify_policy_internal function in lib/kadm5/srv/svr_policy.c in the Kerberos administration daemon (kadmind) in MIT Kerberos 5 (krb5) 1.5 through 1.6.2 does not properly check return values when the policy does not exist, which might allow remote authenticated users with the \"modify policy\" privilege to execute arbitrary code via unspecified vectors that trigger a write to an uninitialized pointer.","state":"PUBLISHED","assigner":"mitre","published_at":"2007-09-05 10:17:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["CWE-824","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"8.5","severity":"","vector":"AV:N/AC:M/Au:S/C:C/I:C/A:C","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:S/C:C/I:C/A:C","baseScore":8.5,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"SINGLE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"}}],"references":[{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/36438","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/36438","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","VDB Entry"],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/26680","name":"http://secunia.com/advisories/26680","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"Fedora update for krb5 - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.redhat.com/support/errata/RHSA-2007-0858.html","name":"http://www.redhat.com/support/errata/RHSA-2007-0858.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"rhn.redhat.com | Red Hat Support","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securitytracker.com/id?1018647","name":"http://www.securitytracker.com/id?1018647","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Third Party Advisory","VDB Entry"],"title":"SecurityTracker.com Archives - Kerberos kadmind Stack Overflow and Uninitialized Pointer Lets Remote Users Execute Arbitrary Code","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.novell.com/linux/security/advisories/2007_19_sr.html","name":"http://www.novell.com/linux/security/advisories/2007_19_sr.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"Security Announcement","mime":"text/html","httpstatus":"404","archivestatus":"200"},{"url":"http://secunia.com/advisories/26676","name":"http://secunia.com/advisories/26676","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"Kerberos Multiple Vulnerabilities - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://issues.rpath.com/browse/RPL-1696","name":"https://issues.rpath.com/browse/RPL-1696","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"[#RPL-1696] RPL:1 krb5 multiple issues CVE-2007-3999 CVE-2007-4743 - rPath Issue Tracking System","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9278","name":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9278","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"Repository  /  Oval Repository","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=250976","name":"https://bugzilla.redhat.com/show_bug.cgi?id=250976","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Issue Tracking"],"title":"Bug 250976 – CVE-2007-4000 krb5 kadmind uninitialized pointer","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://securityreason.com/securityalert/3092","name":"http://securityreason.com/securityalert/3092","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"SecurityReason - MIT krb5 Security Advisory 2007-006","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/25533","name":"http://www.securityfocus.com/bid/25533","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Third Party Advisory","VDB Entry"],"title":"MIT Kerberos 5 kadmind Server Uninitialized Pointer Remote Code Execution Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://secunia.com/advisories/26728","name":"http://secunia.com/advisories/26728","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"Mandriva update for krb5 - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.kb.cert.org/vuls/id/377544","name":"http://www.kb.cert.org/vuls/id/377544","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","US Government Resource"],"title":"US-CERT Vulnerability Note VU#377544","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.mandriva.com/security/advisories?name=MDKSA-2007:174","name":"http://www.mandriva.com/security/advisories?name=MDKSA-2007:174","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"Advisories | Mandriva","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/archive/1/478794/100/0/threaded","name":"http://www.securityfocus.com/archive/1/478794/100/0/threaded","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"],"title":"SecurityFocus","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.redhat.com/archives/fedora-package-announce/2007-September/msg00087.html","name":"https://www.redhat.com/archives/fedora-package-announce/2007-September/msg00087.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List"],"title":"[SECURITY] Fedora 7 Update: krb5-1.6.1-3.fc7","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/26700","name":"http://secunia.com/advisories/26700","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"Red Hat update for krb5 - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2007/3051","name":"http://www.vupen.com/english/advisories/2007/3051","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"Webmail - OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/26987","name":"http://secunia.com/advisories/26987","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"SUSE Update for Multiple Packages - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.gentoo.org/security/en/glsa/glsa-200709-01.xml","name":"http://www.gentoo.org/security/en/glsa/glsa-200709-01.xml","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"Gentoo Linux Documentation\n--\n  MIT Kerberos 5: Multiple vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://web.mit.edu/Kerberos/advisories/MITKRB5-SA-2007-006.txt","name":"http://web.mit.edu/Kerberos/advisories/MITKRB5-SA-2007-006.txt","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"","mime":"text/plain","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/26783","name":"http://secunia.com/advisories/26783","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"Gentoo update for mit-krb5 - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2007-4000","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2007-4000","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2007","cve_id":"4000","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"fedoraproject","cpe5":"fedora","cpe6":"7","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2007","cve_id":"4000","vulnerable":"1","versionEndIncluding":"1.6.2","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"mit","cpe5":"kerberos_5","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T14:37:05.906Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"GLSA-200709-01","tags":["vendor-advisory","x_refsource_GENTOO","x_transferred"],"url":"http://www.gentoo.org/security/en/glsa/glsa-200709-01.xml"},{"name":"FEDORA-2007-2017","tags":["vendor-advisory","x_refsource_FEDORA","x_transferred"],"url":"https://www.redhat.com/archives/fedora-package-announce/2007-September/msg00087.html"},{"name":"SUSE-SR:2007:019","tags":["vendor-advisory","x_refsource_SUSE","x_transferred"],"url":"http://www.novell.com/linux/security/advisories/2007_19_sr.html"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://issues.rpath.com/browse/RPL-1696"},{"name":"26680","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/26680"},{"name":"26783","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/26783"},{"name":"1018647","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://www.securitytracker.com/id?1018647"},{"name":"ADV-2007-3051","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2007/3051"},{"name":"26728","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/26728"},{"name":"26700","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/26700"},{"name":"25533","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/25533"},{"name":"20070907 FLEA-2007-0050-1 krb5 krb5-workstation","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://www.securityfocus.com/archive/1/478794/100/0/threaded"},{"tags":["x_refsource_MISC","x_transferred"],"url":"https://bugzilla.redhat.com/show_bug.cgi?id=250976"},{"name":"26987","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/26987"},{"name":"26676","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/26676"},{"name":"kerberos-modifypolicy-code-execution(36438)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/36438"},{"name":"oval:org.mitre.oval:def:9278","tags":["vdb-entry","signature","x_refsource_OVAL","x_transferred"],"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9278"},{"name":"RHSA-2007:0858","tags":["vendor-advisory","x_refsource_REDHAT","x_transferred"],"url":"http://www.redhat.com/support/errata/RHSA-2007-0858.html"},{"name":"VU#377544","tags":["third-party-advisory","x_refsource_CERT-VN","x_transferred"],"url":"http://www.kb.cert.org/vuls/id/377544"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://web.mit.edu/Kerberos/advisories/MITKRB5-SA-2007-006.txt"},{"name":"3092","tags":["third-party-advisory","x_refsource_SREASON","x_transferred"],"url":"http://securityreason.com/securityalert/3092"},{"name":"MDKSA-2007:174","tags":["vendor-advisory","x_refsource_MANDRIVA","x_transferred"],"url":"http://www.mandriva.com/security/advisories?name=MDKSA-2007:174"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2007-09-04T00:00:00.000Z","descriptions":[{"lang":"en","value":"The kadm5_modify_policy_internal function in lib/kadm5/srv/svr_policy.c in the Kerberos administration daemon (kadmind) in MIT Kerberos 5 (krb5) 1.5 through 1.6.2 does not properly check return values when the policy does not exist, which might allow remote authenticated users with the \"modify policy\" privilege to execute arbitrary code via unspecified vectors that trigger a write to an uninitialized pointer."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2018-10-15T20:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"GLSA-200709-01","tags":["vendor-advisory","x_refsource_GENTOO"],"url":"http://www.gentoo.org/security/en/glsa/glsa-200709-01.xml"},{"name":"FEDORA-2007-2017","tags":["vendor-advisory","x_refsource_FEDORA"],"url":"https://www.redhat.com/archives/fedora-package-announce/2007-September/msg00087.html"},{"name":"SUSE-SR:2007:019","tags":["vendor-advisory","x_refsource_SUSE"],"url":"http://www.novell.com/linux/security/advisories/2007_19_sr.html"},{"tags":["x_refsource_CONFIRM"],"url":"https://issues.rpath.com/browse/RPL-1696"},{"name":"26680","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/26680"},{"name":"26783","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/26783"},{"name":"1018647","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://www.securitytracker.com/id?1018647"},{"name":"ADV-2007-3051","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2007/3051"},{"name":"26728","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/26728"},{"name":"26700","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/26700"},{"name":"25533","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/25533"},{"name":"20070907 FLEA-2007-0050-1 krb5 krb5-workstation","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://www.securityfocus.com/archive/1/478794/100/0/threaded"},{"tags":["x_refsource_MISC"],"url":"https://bugzilla.redhat.com/show_bug.cgi?id=250976"},{"name":"26987","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/26987"},{"name":"26676","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/26676"},{"name":"kerberos-modifypolicy-code-execution(36438)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/36438"},{"name":"oval:org.mitre.oval:def:9278","tags":["vdb-entry","signature","x_refsource_OVAL"],"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9278"},{"name":"RHSA-2007:0858","tags":["vendor-advisory","x_refsource_REDHAT"],"url":"http://www.redhat.com/support/errata/RHSA-2007-0858.html"},{"name":"VU#377544","tags":["third-party-advisory","x_refsource_CERT-VN"],"url":"http://www.kb.cert.org/vuls/id/377544"},{"tags":["x_refsource_CONFIRM"],"url":"http://web.mit.edu/Kerberos/advisories/MITKRB5-SA-2007-006.txt"},{"name":"3092","tags":["third-party-advisory","x_refsource_SREASON"],"url":"http://securityreason.com/securityalert/3092"},{"name":"MDKSA-2007:174","tags":["vendor-advisory","x_refsource_MANDRIVA"],"url":"http://www.mandriva.com/security/advisories?name=MDKSA-2007:174"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2007-4000","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"The kadm5_modify_policy_internal function in lib/kadm5/srv/svr_policy.c in the Kerberos administration daemon (kadmind) in MIT Kerberos 5 (krb5) 1.5 through 1.6.2 does not properly check return values when the policy does not exist, which might allow remote authenticated users with the \"modify policy\" privilege to execute arbitrary code via unspecified vectors that trigger a write to an uninitialized pointer."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"GLSA-200709-01","refsource":"GENTOO","url":"http://www.gentoo.org/security/en/glsa/glsa-200709-01.xml"},{"name":"FEDORA-2007-2017","refsource":"FEDORA","url":"https://www.redhat.com/archives/fedora-package-announce/2007-September/msg00087.html"},{"name":"SUSE-SR:2007:019","refsource":"SUSE","url":"http://www.novell.com/linux/security/advisories/2007_19_sr.html"},{"name":"https://issues.rpath.com/browse/RPL-1696","refsource":"CONFIRM","url":"https://issues.rpath.com/browse/RPL-1696"},{"name":"26680","refsource":"SECUNIA","url":"http://secunia.com/advisories/26680"},{"name":"26783","refsource":"SECUNIA","url":"http://secunia.com/advisories/26783"},{"name":"1018647","refsource":"SECTRACK","url":"http://www.securitytracker.com/id?1018647"},{"name":"ADV-2007-3051","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2007/3051"},{"name":"26728","refsource":"SECUNIA","url":"http://secunia.com/advisories/26728"},{"name":"26700","refsource":"SECUNIA","url":"http://secunia.com/advisories/26700"},{"name":"25533","refsource":"BID","url":"http://www.securityfocus.com/bid/25533"},{"name":"20070907 FLEA-2007-0050-1 krb5 krb5-workstation","refsource":"BUGTRAQ","url":"http://www.securityfocus.com/archive/1/478794/100/0/threaded"},{"name":"https://bugzilla.redhat.com/show_bug.cgi?id=250976","refsource":"MISC","url":"https://bugzilla.redhat.com/show_bug.cgi?id=250976"},{"name":"26987","refsource":"SECUNIA","url":"http://secunia.com/advisories/26987"},{"name":"26676","refsource":"SECUNIA","url":"http://secunia.com/advisories/26676"},{"name":"kerberos-modifypolicy-code-execution(36438)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/36438"},{"name":"oval:org.mitre.oval:def:9278","refsource":"OVAL","url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9278"},{"name":"RHSA-2007:0858","refsource":"REDHAT","url":"http://www.redhat.com/support/errata/RHSA-2007-0858.html"},{"name":"VU#377544","refsource":"CERT-VN","url":"http://www.kb.cert.org/vuls/id/377544"},{"name":"http://web.mit.edu/Kerberos/advisories/MITKRB5-SA-2007-006.txt","refsource":"CONFIRM","url":"http://web.mit.edu/Kerberos/advisories/MITKRB5-SA-2007-006.txt"},{"name":"3092","refsource":"SREASON","url":"http://securityreason.com/securityalert/3092"},{"name":"MDKSA-2007:174","refsource":"MANDRIVA","url":"http://www.mandriva.com/security/advisories?name=MDKSA-2007:174"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2007-4000","datePublished":"2007-09-05T10:00:00.000Z","dateReserved":"2007-07-25T00:00:00.000Z","dateUpdated":"2024-08-07T14:37:05.906Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2007-09-05 10:17:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["CWE-824","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:S/C:C/I:C/A:C","baseScore":8.5,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"SINGLE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":6.8,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:mit:kerberos_5:*:*:*:*:*:*:*:*","versionStartIncluding":"1.5","versionEndIncluding":"1.6.2","matchCriteriaId":"FA78988C-2288-47F6-9E90-9804CC38E3DB"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:fedoraproject:fedora:7:*:*:*:*:*:*:*","matchCriteriaId":"E3EFD171-01F7-450B-B6F3-0F7E443A2337"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2007","CveId":"4000","Ordinal":"1","Title":"CVE-2007-4000","CVE":"CVE-2007-4000","Year":"2007"},"notes":[{"CveYear":"2007","CveId":"4000","Ordinal":"1","NoteData":"The kadm5_modify_policy_internal function in lib/kadm5/srv/svr_policy.c in the Kerberos administration daemon (kadmind) in MIT Kerberos 5 (krb5) 1.5 through 1.6.2 does not properly check return values when the policy does not exist, which might allow remote authenticated users with the \"modify policy\" privilege to execute arbitrary code via unspecified vectors that trigger a write to an uninitialized pointer.","Type":"Description","Title":"CVE-2007-4000"},{"CveYear":"2007","CveId":"4000","Ordinal":"2","NoteData":"2007-09-05","Type":"Other","Title":"Published"},{"CveYear":"2007","CveId":"4000","Ordinal":"3","NoteData":"2018-10-15","Type":"Other","Title":"Modified"}]}}}