The Kerberos 4 support in KDC in MIT Kerberos 5 (krb5kdc) does not properly clear the unused portion of a buffer when generating an error message, which might allow remote attackers to obtain sensitive information, aka "Uninitialized stack values."
References
Configurations
Configuration 1 (hide)
AND |
|
Information
Published : 2008-03-19 03:44
Updated : 2018-10-15 14:57
NVD link : CVE-2008-0063
Mitre link : CVE-2008-0063
JSON object : View
CWE
CWE-119
Improper Restriction of Operations within the Bounds of a Memory Buffer
Products Affected
apple
- mac_os_x
- mac_os_x_server
mit
- kerberos_5