CVE-2008-0948

Impact:
Moderate
Public Date:
2008-03-18
Bugzilla:
435087: CVE-2008-0948 krb5: incorrect handling of high-numbered file descriptors in RPC library

The MITRE CVE dictionary describes this issue as:

Buffer overflow in the RPC library (lib/rpc/rpc_dtablesize.c) used by libgssrpc and kadmind in MIT Kerberos 5 (krb5) 1.2.2, and probably other versions before 1.3, when running on systems whose unistd.h does not define the FD_SETSIZE macro, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code by triggering a large number of open file descriptors.

Find out more about CVE-2008-0948 from the MITRE CVE dictionary dictionary and NIST NVD.

Red Hat Security Errata

Platform Errata Release Date
Red Hat Enterprise Linux 3 (krb5) RHSA-2008:0181 2008-03-18
Red Hat Enterprise Linux 2.1 (krb5) RHSA-2008:0181 2008-03-18

Acknowledgements

Red Hat would like to thank MIT for reporting this issue.

Last Modified

CVE description copyright © 2017, The MITRE Corporation

Close

Welcome! Check out the Getting Started with Red Hat page for quick tours and guides for common tasks.