The Kerberos 4 support in KDC in MIT Kerberos 5 (krb5kdc) does not properly clear the unused portion of a buffer when generating an error message, which might allow remote attackers to obtain sensitive information, aka "Uninitialized stack values."
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
Configuration 4 (hide)
|
Configuration 5 (hide)
|
Configuration 6 (hide)
|
History
No history.
Information
Published : 2008-03-19 10:44
Updated : 2024-02-09 00:35
NVD link : CVE-2008-0063
Mitre link : CVE-2008-0063
CVE.ORG link : CVE-2008-0063
JSON object : View
Products Affected
suse
- linux_enterprise_desktop
- linux
- linux_enterprise_server
- linux_enterprise_software_development_kit
apple
- mac_os_x
- mac_os_x_server
canonical
- ubuntu_linux
fedoraproject
- fedora
debian
- debian_linux
opensuse
- opensuse
mit
- kerberos_5
CWE
CWE-908
Use of Uninitialized Resource