CVE-2008-0063
published 2008-03-19CVE-2008-0063: The Kerberos 4 support in KDC in MIT Kerberos 5 (krb5kdc) does not properly clear the unused portion of a buffer when generating an error message, which might…
PriorityP429high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
3.48%
87.8th percentile
The Kerberos 4 support in KDC in MIT Kerberos 5 (krb5kdc) does not properly clear the unused portion of a buffer when generating an error message, which might allow remote attackers to obtain sensitive information, aka "Uninitialized stack values."
Affected
29 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | mac_os_x | < 10.4.11 | 10.4.11 |
| apple | mac_os_x | >= 10.5.0 < 10.5.2 | 10.5.2 |
| apple | mac_os_x_server | < 10.4.11 | 10.4.11 |
| apple | mac_os_x_server | >= 10.5.0 < 10.5.2 | 10.5.2 |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | krb5 | < krb5 1.6.dfsg.3~beta1-4 (bookworm) | krb5 1.6.dfsg.3~beta1-4 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| github.com | migueldeicaza_swiftterm | >= 0 < 1.2.0 | 1.2.0 |
| mit | kerberos_5 | <= 1.6.3 | — |
| mit | krb5 | >= 0 < 1.6.dfsg.3~beta1-4 | 1.6.dfsg.3~beta1-4 |
| mit | krb5 | >= 0 < 1.6.dfsg.3~beta1-4 | 1.6.dfsg.3~beta1-4 |
| mit | krb5 | >= 0 < 1.6.dfsg.3~beta1-4 | 1.6.dfsg.3~beta1-4 |
| mit | krb5 | >= 0 < 1.6.dfsg.3~beta1-4 | 1.6.dfsg.3~beta1-4 |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
| suse | linux | — | — |
| suse | linux_enterprise_desktop | — | — |
| suse | linux_enterprise_server | — | — |
| suse | linux_enterprise_software_development_kit | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
ghsa7.3HIGH
osv7.5HIGH
vendor_ubuntu9.8CRITICAL
vendor_debian7.5MEDIUM
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
xterm: arbitrary command injection
vendor_redhat·2008-12-29·CVSS 7.3
CVE-2008-2383 [HIGH] xterm: arbitrary command injection
xterm: arbitrary command injection
CRLF injection vulnerability in xterm allows user-assisted attackers to execute arbitrary commands via LF (aka \n) characters surrounding a command name within a Device Control Request Status String (DECRQSS) escape sequence in a text file, a related issue to CVE-2003-0063 and CVE-2003-0071.
VMware
Updates to VMware Workstation, VMware Player, VMware ACE, VMware Fusion, VMware Server, VMware VIX API, VMware ESX, VMware ESXi resolve critical security issues
vendor_vmware·2008-06-04·CVSS 2.6
CVE-2006-1721 [LOW] Updates to VMware Workstation, VMware Player, VMware ACE, VMware Fusion, VMware Server, VMware VIX API, VMware ESX, VMware ESXi resolve critical security issues
VMSA-2008-0009: Updates to VMware Workstation, VMware Player, VMware ACE, VMware Fusion, VMware Server, VMware VIX API, VMware ESX, VMware ESXi resolve critical security issues
Updates to VMware Workstation, VMware Player, VMware ACE, VMware Fusion, VMware Server, VMware VIX API, VMware ESX, VMware ESXi resolve critical security issues VMware Security Advisory VMware Security AdvisoryAdvisory ID: VMware Security AdvisorySynopsis: Updates to VMware Workstation, VMware Player, VMware ACE, VMware Fusion, VMware Server, VMware VIX API, VMware ESX, VMware ESXi resolve critical security issues VMware Security AdvisoryIssue date: VMware Security AdvisoryUpdated on:
CVEs: CVE-2006-1721, CVE-2007-4772, CVE-2007-5378, CVE-2007-5671, CVE-2008-0062, CVE-2008-0063, CVE-2008-0553, CVE-2008-0888, CVE-2
Ubuntu
Kerberos vulnerabilities
vendor_ubuntu·2008-03-19·CVSS 9.8
CVE-2008-0062 [CRITICAL] Kerberos vulnerabilities
Title: Kerberos vulnerabilities
Summary: Kerberos vulnerabilities
It was discovered that krb5 did not correctly handle certain krb4
requests. An unauthenticated remote attacker could exploit this flaw
by sending a specially crafted traffic, which could expose sensitive
information, cause a crash, or execute arbitrary code. (CVE-2008-0062,
CVE-2008-0063)
A flaw was discovered in the kadmind service's handling of file
descriptors. An unauthenticated remote attacker could send specially
crafted requests that would cause a crash, resulting in a denial of
service. Only systems with configurations allowing large numbers of
open file descriptors were vulnerable. (CVE-2008-0947)
Instructions: In general, a standard system upgrade is sufficient to effect the
necessary changes.
Red Hat
krb5: possible leak of sensitive data from krb5kdc using krb4 request
vendor_redhat·2008-03-18·CVSS 7.5
CVE-2008-0063 [HIGH] krb5: possible leak of sensitive data from krb5kdc using krb4 request
krb5: possible leak of sensitive data from krb5kdc using krb4 request
The Kerberos 4 support in KDC in MIT Kerberos 5 (krb5kdc) does not properly clear the unused portion of a buffer when generating an error message, which might allow remote attackers to obtain sensitive information, aka "Uninitialized stack values."
Debian
CVE-2008-0063: krb5 - The Kerberos 4 support in KDC in MIT Kerberos 5 (krb5kdc) does not properly clea...
vendor_debian·2008·CVSS 7.5
CVE-2008-0063 [HIGH] CVE-2008-0063: krb5 - The Kerberos 4 support in KDC in MIT Kerberos 5 (krb5kdc) does not properly clea...
The Kerberos 4 support in KDC in MIT Kerberos 5 (krb5kdc) does not properly clear the unused portion of a buffer when generating an error message, which might allow remote attackers to obtain sensitive information, aka "Uninitialized stack values."
Scope: local
bookworm: resolved (fixed in 1.6.dfsg.3~beta1-4)
bullseye: resolved (fixed in 1.6.dfsg.3~beta1-4)
forky: resolved (fixed in 1.6.dfsg.3~beta1-4)
sid: resolved (fixed in 1.6.dfsg.3~beta1-4)
trixie: resolved (fixed in 1.6.dfsg.3~beta1-4)
GHSA
SwiftTerm Code Injection vulnerability
ghsa·2023-07-14·CVSS 7.3
CVE-2022-23465 [HIGH] CWE-94 SwiftTerm Code Injection vulnerability
SwiftTerm Code Injection vulnerability
### Impact
Attacker could modify the window title via a certain character escape sequence and then insert it back to the command line in the user's terminal, e.g. when the user views a file containing the malicious sequence, which could allow the attacker to execute arbitrary commands.
### Credit
These bugs were found and disclosed by David Leadbeater (@dgl at Github.com)
### Patches
Fixed in version ce596e0dc8cdb288bc7ed5c6a59011ee3a8dc171
### Workarounds
There are no workarounds available
### References
Similar exploits to this existed in the past, for terminal emulators:
https://nvd.nist.gov/vuln/detail/CVE-2003-0063
https://nvd.nist.gov/vuln/detail/CVE-2008-2383
Additional background and information is also available:
https://marc.info
GHSA
GHSA-67px-r9v8-hcfg: The Kerberos 4 support in KDC in MIT Kerberos 5 (krb5kdc) does not properly clear the unused portion of a buffer when generating an error message, whi
ghsa_unreviewed·2022-05-01
CVE-2008-0063 [MEDIUM] CWE-119 GHSA-67px-r9v8-hcfg: The Kerberos 4 support in KDC in MIT Kerberos 5 (krb5kdc) does not properly clear the unused portion of a buffer when generating an error message, whi
The Kerberos 4 support in KDC in MIT Kerberos 5 (krb5kdc) does not properly clear the unused portion of a buffer when generating an error message, which might allow remote attackers to obtain sensitive information, aka "Uninitialized stack values."
OSV
CVE-2008-0063: The Kerberos 4 support in KDC in MIT Kerberos 5 (krb5kdc) does not properly clear the unused portion of a buffer when generating an error message, whi
osv·2008-03-19·CVSS 7.5
CVE-2008-0063 [HIGH] CVE-2008-0063: The Kerberos 4 support in KDC in MIT Kerberos 5 (krb5kdc) does not properly clear the unused portion of a buffer when generating an error message, whi
The Kerberos 4 support in KDC in MIT Kerberos 5 (krb5kdc) does not properly clear the unused portion of a buffer when generating an error message, which might allow remote attackers to obtain sensitive information, aka "Uninitialized stack values."
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2008-0062 krb5: uninitialized pointer use in krb5kdc
bugzilla·2008-02-13·CVSS 9.8
CVE-2008-0062 [CRITICAL] CVE-2008-0062 krb5: uninitialized pointer use in krb5kdc
CVE-2008-0062 krb5: uninitialized pointer use in krb5kdc
MIT Kerberos Team reported following issue affecting MIT Kerberos 5 KDC with
Kerberos 4 support enabled:
CVE-2008-0062: A global variable holding a pointer to the message to
be sent back to the client is only set for two recognized krb4 message
types, but may be used (and freed) in additional cases, resulting in
use of a null or dangling pointer.
Acknowledgements:
Red Hat would like to thank MIT for reporting this issue.
Discussion:
Created attachment 294787
Upstream patch for CVE-2008-0062 and CVE-2008-0063
---
This issue affects krb5 packages as shipped in Red Hat Enterprise Linux 2.1, 3,
4 and 5 and current versions of Fedora. Support for Kerberos v4 is not assumed
by default by krb5kdc on Red Hat Enterprise Linux 5 and Fe
Bugzilla
CVE-2008-0063 krb5: possible leak of sensitive data from krb5kdc using krb4 request
bugzilla·2008-02-13·CVSS 7.5
CVE-2008-0063 [HIGH] CVE-2008-0063 krb5: possible leak of sensitive data from krb5kdc using krb4 request
CVE-2008-0063 krb5: possible leak of sensitive data from krb5kdc using krb4 request
MIT Kerberos Team reported following issue affecting MIT Kerberos 5 KDC with
Kerberos 4 support enabled:
CVE-2008-0063: The incoming krb4 message is copied into a fixed-size
buffer on the stack, but the remainder of the buffer is left
untouched, and the bounds checks use the size of the buffer, not the
size of the data copied into it.
Acknowledgements:
Red Hat would like to thank MIT for reporting this issue.
Discussion:
See bug bug #432620 for patch.
---
This issue affects krb5 packages as shipped in Red Hat Enterprise Linux 2.1, 3,
4 and 5 and current versions of Fedora. Support for Kerberos v4 is not assumed
by default by krb5kdc on Red Hat Enterprise Linux 5 and Fedora, however default
configura
CWE
Improper Initialization
mitre_cwe
CWE-665 Improper Initialization
CWE-665: Improper Initialization
The product does not initialize or incorrectly initializes a resource, which might leave the resource in an unexpected state when it is accessed or used.
This can have security implications when the associated resource is expected to have certain properties or values, such as a variable that determines whether a user has been authenticated or not.
Modes of Introduction:
Phase: Implementation
Note: This weakness can occur in code paths that are not well-tested, such as rare error conditions. This is because the use of uninitialized data would be noticed as a bug during frequently-used functionality.
Phase: Operation
Common Consequences:
Scope: Confidentiality. Impact: Read Memory, Read Application Data. When reusing a resource such as memory or a program
CWE
Use of Uninitialized Resource
mitre_cwe
CWE-908 Use of Uninitialized Resource
CWE-908: Use of Uninitialized Resource
The product uses or accesses a resource that has not been initialized.
When a resource has not been properly initialized, the product may behave unexpectedly. This may lead to a crash or invalid memory access, but the consequences vary depending on the type of resource and how it is used within the product.
Modes of Introduction:
Phase: Implementation
Common Consequences:
Scope: Confidentiality. Impact: Read Memory, Read Application Data. When reusing a resource such as memory or a program variable, the original contents of that resource may not be cleared before it is sent to an untrusted party.
Scope: Availability. Impact: DoS: Crash, Exit, or Restart. The uninitialized resource may contain values that cause program flow to change in ways that t
http://docs.info.apple.com/article.html?artnum=307562http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2008-03/msg00006.htmlhttp://secunia.com/advisories/29420http://secunia.com/advisories/29423http://secunia.com/advisories/29424http://secunia.com/advisories/29428http://secunia.com/advisories/29435http://secunia.com/advisories/29438http://secunia.com/advisories/29450http://secunia.com/advisories/29451http://secunia.com/advisories/29457http://secunia.com/advisories/29462http://secunia.com/advisories/29464http://secunia.com/advisories/29516http://secunia.com/advisories/29663http://secunia.com/advisories/30535http://support.novell.com/docs/Readmes/InfoDocument/patchbuilder/readme_5022520.htmlhttp://support.novell.com/docs/Readmes/InfoDocument/patchbuilder/readme_5022542.htmlhttp://web.mit.edu/kerberos/advisories/MITKRB5-SA-2008-001.txthttp://wiki.rpath.com/Advisories:rPSA-2008-0112http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0112http://www.debian.org/security/2008/dsa-1524http://www.gentoo.org/security/en/glsa/glsa-200803-31.xmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2008:069http://www.mandriva.com/security/advisories?name=MDVSA-2008:070http://www.mandriva.com/security/advisories?name=MDVSA-2008:071http://www.redhat.com/support/errata/RHSA-2008-0164.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0180.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0181.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0182.htmlhttp://www.securityfocus.com/archive/1/489761http://www.securityfocus.com/archive/1/489883/100/0/threadedhttp://www.securityfocus.com/archive/1/493080/100/0/threadedhttp://www.securityfocus.com/bid/28303http://www.securitytracker.com/id?1019627http://www.ubuntu.com/usn/usn-587-1http://www.vmware.com/security/advisories/VMSA-2008-0009.htmlhttp://www.vupen.com/english/advisories/2008/0922/referenceshttp://www.vupen.com/english/advisories/2008/0924/referenceshttp://www.vupen.com/english/advisories/2008/1102/referenceshttp://www.vupen.com/english/advisories/2008/1744https://exchange.xforce.ibmcloud.com/vulnerabilities/41277https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8916https://www.redhat.com/archives/fedora-package-announce/2008-March/msg00537.htmlhttps://www.redhat.com/archives/fedora-package-announce/2008-March/msg00544.htmlhttp://docs.info.apple.com/article.html?artnum=307562http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2008-03/msg00006.htmlhttp://secunia.com/advisories/29420http://secunia.com/advisories/29423http://secunia.com/advisories/29424http://secunia.com/advisories/29428http://secunia.com/advisories/29435http://secunia.com/advisories/29438http://secunia.com/advisories/29450http://secunia.com/advisories/29451http://secunia.com/advisories/29457http://secunia.com/advisories/29462http://secunia.com/advisories/29464http://secunia.com/advisories/29516http://secunia.com/advisories/29663http://secunia.com/advisories/30535http://support.novell.com/docs/Readmes/InfoDocument/patchbuilder/readme_5022520.htmlhttp://support.novell.com/docs/Readmes/InfoDocument/patchbuilder/readme_5022542.htmlhttp://web.mit.edu/kerberos/advisories/MITKRB5-SA-2008-001.txthttp://wiki.rpath.com/Advisories:rPSA-2008-0112http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0112http://www.debian.org/security/2008/dsa-1524http://www.gentoo.org/security/en/glsa/glsa-200803-31.xmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2008:069http://www.mandriva.com/security/advisories?name=MDVSA-2008:070http://www.mandriva.com/security/advisories?name=MDVSA-2008:071http://www.redhat.com/support/errata/RHSA-2008-0164.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0180.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0181.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0182.htmlhttp://www.securityfocus.com/archive/1/489761http://www.securityfocus.com/archive/1/489883/100/0/threadedhttp://www.securityfocus.com/archive/1/493080/100/0/threadedhttp://www.securityfocus.com/bid/28303http://www.securitytracker.com/id?1019627http://www.ubuntu.com/usn/usn-587-1http://www.vmware.com/security/advisories/VMSA-2008-0009.htmlhttp://www.vupen.com/english/advisories/2008/0922/referenceshttp://www.vupen.com/english/advisories/2008/0924/referenceshttp://www.vupen.com/english/advisories/2008/1102/referenceshttp://www.vupen.com/english/advisories/2008/1744https://exchange.xforce.ibmcloud.com/vulnerabilities/41277https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8916https://www.redhat.com/archives/fedora-package-announce/2008-March/msg00537.htmlhttps://www.redhat.com/archives/fedora-package-announce/2008-March/msg00544.html
2008-03-19
Published