CVE-2008-0063

Description

From CVE.org

The Kerberos 4 support in KDC in MIT Kerberos 5 (krb5kdc) does not properly clear the unused portion of a buffer when generating an error message, which might allow remote attackers to obtain sensitive information, aka "Uninitialized stack values."

Acknowledgements

Red Hat would like to thank MIT for reporting this issue.

Frequently Asked Questions

Want to get errata notifications? Sign up here.