← Vulnerability feed

Vulnerability record · CVE-2006-6144 · published 31 December 2006

CVE-2006-6144: Mit kerberos 5 vulnerability

Mit · Kerberos 5

The "mechglue" abstraction interface of the GSS-API library for Kerberos 5 1.5 through 1.5.1, as used in Kerberos administration daemon (kadmind) and other products that use this library, allows remote attackers to cause a denial of service (crash) via unspecified vectors that cause mechglue to free uninitialized pointers.

5.0 CVSS 2.0 Medium EPSS 5.4% · top 7.6%
5.0CVSS 2.0 base score
5.4%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
44References
16 Jun 2026Last modified by NVD

Description

The "mechglue" abstraction interface of the GSS-API library for Kerberos 5 1.5 through 1.5.1, as used in Kerberos administration daemon (kadmind) and other products that use this library, allows remote attackers to cause a denial of service (crash) via unspecified vectors that cause mechglue to free uninitialized pointers.

AV:N/AC:L/Au:N/C:N/I:N/A:P

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://fedoranews.org/cms/node/2375 Broken Link
http://lists.suse.com/archive/suse-security-announce/2007-Jan/0004.html Broken Link
http://osvdb.org/31280 Broken Link
http://secunia.com/advisories/23690 Third Party Advisory
http://secunia.com/advisories/23701 Third Party Advisory
http://secunia.com/advisories/23706 Third Party Advisory
http://secunia.com/advisories/23903 Third Party Advisory
http://secunia.com/advisories/35151 Third Party Advisory
http://security.gentoo.org/glsa/glsa-200701-21.xml Third Party Advisory
http://securitytracker.com/id?1017494 Third Party AdvisoryVDB Entry
http://sunsolve.sun.com/search/document.do?assetkey=1-26-102772-1 Broken Link
http://sunsolve.sun.com/search/document.do?assetkey=1-26-201294-1 Broken Link
http://web.mit.edu/kerberos/www/advisories/MITKRB5-SA-2006-003-mechglue.txt PatchVendor Advisory
http://www.kb.cert.org/vuls/id/831452 Third Party AdvisoryUS Government Resource
http://www.openpkg.com/security/advisories/OpenPKG-SA-2007.006.html Third Party Advisory
http://www.securityfocus.com/archive/1/456409/100/0/threaded Third Party AdvisoryVDB Entry
http://www.securityfocus.com/bid/21975 Third Party AdvisoryVDB Entry
http://www.us-cert.gov/cas/techalerts/TA07-009B.html Third Party AdvisoryUS Government Resource
http://www.vupen.com/english/advisories/2007/0111 Third Party Advisory
http://www.vupen.com/english/advisories/2007/0112 Third Party Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/31417 Third Party AdvisoryVDB Entry
https://issues.rpath.com/browse/RPL-925 Broken Link
http://fedoranews.org/cms/node/2375 Broken Link
http://lists.suse.com/archive/suse-security-announce/2007-Jan/0004.html Broken Link
http://osvdb.org/31280 Broken Link
http://secunia.com/advisories/23690 Third Party Advisory
http://secunia.com/advisories/23701 Third Party Advisory
http://secunia.com/advisories/23706 Third Party Advisory
http://secunia.com/advisories/23903 Third Party Advisory
http://secunia.com/advisories/35151 Third Party Advisory
http://security.gentoo.org/glsa/glsa-200701-21.xml Third Party Advisory
http://securitytracker.com/id?1017494 Third Party AdvisoryVDB Entry
http://sunsolve.sun.com/search/document.do?assetkey=1-26-102772-1 Broken Link
http://sunsolve.sun.com/search/document.do?assetkey=1-26-201294-1 Broken Link
http://web.mit.edu/kerberos/www/advisories/MITKRB5-SA-2006-003-mechglue.txt PatchVendor Advisory
http://www.kb.cert.org/vuls/id/831452 Third Party AdvisoryUS Government Resource
http://www.openpkg.com/security/advisories/OpenPKG-SA-2007.006.html Third Party Advisory
http://www.securityfocus.com/archive/1/456409/100/0/threaded Third Party AdvisoryVDB Entry
http://www.securityfocus.com/bid/21975 Third Party AdvisoryVDB Entry
http://www.us-cert.gov/cas/techalerts/TA07-009B.html Third Party AdvisoryUS Government Resource

Track CVE-2006-6144 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2011-0285Mit kerberos 5 improper input validation vulnerabilityThe process_chpw_request function in schpw.c in the password-changing functionality in kadmind in MIT Kerberos 5 (aka krb5) 1.7 through 1.9 frees an …EPSS 21%10.0CVE-2009-4212Mit kerberos vulnerabilityMultiple integer underflows in the (1) AES and (2) RC4 decryption functionality in the crypto library in MIT Kerberos 5 (aka krb5) 1.3 through 1.6.3,…EPSS 7.6%10.0CVE-2009-0846Mit kerberos 5 vulnerabilityThe asn1_decode_generaltime function in lib/krb5/asn.1/asn1_decode.c in the ASN.1 GeneralizedTime decoder in MIT Kerberos 5 (aka krb5) before 1.6.4 a…EPSS 8.9%10.0CVE-2008-0947Mit kerberos 5 memory buffer overflow vulnerabilityBuffer overflow in the RPC library used by libgssrpc and kadmind in MIT Kerberos 5 (krb5) 1.4 through 1.6.3 allows remote attackers to execute arbitr…EPSS 8.8%10.0CVE-2007-5902Mit kerberos 5 vulnerabilityInteger overflow in the svcauth_gss_get_principal function in lib/rpc/svc_auth_gss.c in MIT Kerberos 5 (krb5) allows remote attackers to have an unkn…EPSS 5.9%10.0CVE-2007-4743Mit kerberos 5 memory buffer overflow vulnerabilityThe original patch for CVE-2007-3999 in svc_auth_gss.c in the RPCSEC_GSS RPC library in MIT Kerberos 5 (krb5) 1.4 through 1.6.2, as used by the Kerbe…EPSS 4.6%10.0CVE-2007-3999Mit kerberos 5 memory buffer overflow vulnerabilityStack-based buffer overflow in the svcauth_gss_validate function in lib/rpc/svc_auth_gss.c in the RPCSEC_GSS RPC library (librpcsecgss) in MIT Kerber…EPSS 11%10.0CVE-2007-2442Mit kerberos 5 vulnerabilityThe gssrpc__svcauth_gssapi function in the RPC library in MIT Kerberos 5 (krb5) 1.6.1 and earlier might allow remote attackers to execute arbitrary c…EPSS 11%

Source: NIST National Vulnerability Database (record CVE-2006-6144), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.