CVE-2008-0063

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
19/03/2008
Last modified:
09/04/2025

Description

The Kerberos 4 support in KDC in MIT Kerberos 5 (krb5kdc) does not properly clear the unused portion of a buffer when generating an error message, which might allow remote attackers to obtain sensitive information, aka "Uninitialized stack values."

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:mit:kerberos_5:*:*:*:*:*:*:*:* 1.6.3 (including)
cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:* 10.4.11 (excluding)
cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:* 10.5.0 (including) 10.5.2 (excluding)
cpe:2.3:o:apple:mac_os_x_server:*:*:*:*:*:*:*:* 10.4.11 (excluding)
cpe:2.3:o:apple:mac_os_x_server:*:*:*:*:*:*:*:* 10.5.0 (including) 10.5.2 (excluding)
cpe:2.3:o:opensuse:opensuse:10.2:*:*:*:*:*:*:*
cpe:2.3:o:opensuse:opensuse:10.3:*:*:*:*:*:*:*
cpe:2.3:o:suse:linux:10.1:*:*:*:*:*:*:*
cpe:2.3:o:suse:linux_enterprise_desktop:10:sp1:*:*:*:*:*:*
cpe:2.3:o:suse:linux_enterprise_server:10:sp1:*:*:*:*:*:*
cpe:2.3:o:suse:linux_enterprise_software_development_kit:10:sp1:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:3.1:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:4.0:*:*:*:*:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:6.06:*:*:*:*:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:6.10:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools