cbcvebase.
CVE-2008-0063
published 2008-03-19

CVE-2008-0063: The Kerberos 4 support in KDC in MIT Kerberos 5 (krb5kdc) does not properly clear the unused portion of a buffer when generating an error message, which might…

high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
The Kerberos 4 support in KDC in MIT Kerberos 5 (krb5kdc) does not properly clear the unused portion of a buffer when generating an error message, which might allow remote attackers to obtain sensitive information, aka "Uninitialized stack values."

Affected

29 ranges· showing 25
VendorProductVersion rangeFixed in
applemac_os_x< 10.4.1110.4.11
applemac_os_x>= 10.5.0 < 10.5.210.5.2
applemac_os_x_server< 10.4.1110.4.11
applemac_os_x_server>= 10.5.0 < 10.5.210.5.2
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debiandebian_linux
debiandebian_linux
debiankrb5< krb5 1.6.dfsg.3~beta1-4 (bookworm)krb5 1.6.dfsg.3~beta1-4 (bookworm)
fedoraprojectfedora
fedoraprojectfedora
github.commigueldeicaza_swiftterm>= 0 < 1.2.01.2.0
mitkerberos_5<= 1.6.3
mitkrb5>= 0 < 1.6.dfsg.3~beta1-41.6.dfsg.3~beta1-4
mitkrb5>= 0 < 1.6.dfsg.3~beta1-41.6.dfsg.3~beta1-4
mitkrb5>= 0 < 1.6.dfsg.3~beta1-41.6.dfsg.3~beta1-4
mitkrb5>= 0 < 1.6.dfsg.3~beta1-41.6.dfsg.3~beta1-4
opensuseopensuse
opensuseopensuse
suselinux
suselinux_enterprise_desktop
suselinux_enterprise_server
suselinux_enterprise_software_development_kit

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
ghsa7.3HIGH
osv7.5HIGH