← Vulnerability feed

Vulnerability record · CVE-2007-3999 · published 5 September 2007

CVE-2007-3999: Mit kerberos 5 memory buffer overflow vulnerability

Mit · Kerberos 5

Stack-based buffer overflow in the svcauth_gss_validate function in lib/rpc/svc_auth_gss.c in the RPCSEC_GSS RPC library (librpcsecgss) in MIT Kerberos 5 (krb5) 1.4 through 1.6.2, as used by the Kerberos administration daemon (kadmind) and some third-party applications that use krb5, allows remote attackers to cause a denial of service (daemon crash) and probably execute arbitrary code via a long string in an RPC message.

10.0 CVSS 2.0 High EPSS 11% · top 4.2% CWE-119 · Memory buffer overflow
10.0CVSS 2.0 base score
11%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
124References
16 Jun 2026Last modified by NVD

Description

Stack-based buffer overflow in the svcauth_gss_validate function in lib/rpc/svc_auth_gss.c in the RPCSEC_GSS RPC library (librpcsecgss) in MIT Kerberos 5 (krb5) 1.4 through 1.6.2, as used by the Kerberos administration daemon (kadmind) and some third-party applications that use krb5, allows remote attackers to cause a denial of service (daemon crash) and probably execute arbitrary code via a long string in an RPC message.

AV:N/AC:L/Au:N/C:C/I:C/A:C

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://docs.info.apple.com/article.html?artnum=307041
http://lists.apple.com/archives/security-announce/2007/Nov/msg00002.html
http://lists.rpath.com/pipermail/security-announce/2007-September/000237.html
http://secunia.com/advisories/26676 Vendor Advisory
http://secunia.com/advisories/26680 Vendor Advisory
http://secunia.com/advisories/26684 Vendor Advisory
http://secunia.com/advisories/26691 Vendor Advisory
http://secunia.com/advisories/26697 Vendor Advisory
http://secunia.com/advisories/26699 Vendor Advisory
http://secunia.com/advisories/26700 Vendor Advisory
http://secunia.com/advisories/26705 Vendor Advisory
http://secunia.com/advisories/26713 Vendor Advisory
http://secunia.com/advisories/26728 Vendor Advisory
http://secunia.com/advisories/26783 Vendor Advisory
http://secunia.com/advisories/26792 Vendor Advisory
http://secunia.com/advisories/26822 Vendor Advisory
http://secunia.com/advisories/26896 Vendor Advisory
http://secunia.com/advisories/26987 Vendor Advisory
http://secunia.com/advisories/27043 Vendor Advisory
http://secunia.com/advisories/27081 Vendor Advisory
http://secunia.com/advisories/27146 Vendor Advisory
http://secunia.com/advisories/27643 Vendor Advisory
http://secunia.com/advisories/27756
http://secunia.com/advisories/29247
http://secunia.com/advisories/29270
http://security.gentoo.org/glsa/glsa-200710-01.xml
http://securityreason.com/securityalert/3092
http://sunsolve.sun.com/search/document.do?assetkey=1-26-103060-1
http://sunsolve.sun.com/search/document.do?assetkey=1-66-201319-1
http://support.avaya.com/elmodocs2/security/ASA-2007-396.htm
http://web.mit.edu/Kerberos/advisories/MITKRB5-SA-2007-006.txt
http://www.debian.org/security/2007/dsa-1367
http://www.debian.org/security/2007/dsa-1368
http://www.gentoo.org/security/en/glsa/glsa-200709-01.xml
http://www.kb.cert.org/vuls/id/883632 US Government Resource
http://www.mandriva.com/security/advisories?name=MDKSA-2007:174
http://www.mandriva.com/security/advisories?name=MDKSA-2007:181
http://www.novell.com/linux/security/advisories/2007_19_sr.html
http://www.novell.com/linux/security/advisories/2007_24_sr.html
http://www.redhat.com/support/errata/RHSA-2007-0858.html

Track CVE-2007-3999 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2011-0285Mit kerberos 5 improper input validation vulnerabilityThe process_chpw_request function in schpw.c in the password-changing functionality in kadmind in MIT Kerberos 5 (aka krb5) 1.7 through 1.9 frees an …EPSS 21%10.0CVE-2009-4212Mit kerberos vulnerabilityMultiple integer underflows in the (1) AES and (2) RC4 decryption functionality in the crypto library in MIT Kerberos 5 (aka krb5) 1.3 through 1.6.3,…EPSS 7.6%10.0CVE-2009-0846Mit kerberos 5 vulnerabilityThe asn1_decode_generaltime function in lib/krb5/asn.1/asn1_decode.c in the ASN.1 GeneralizedTime decoder in MIT Kerberos 5 (aka krb5) before 1.6.4 a…EPSS 8.9%10.0CVE-2008-0947Mit kerberos 5 memory buffer overflow vulnerabilityBuffer overflow in the RPC library used by libgssrpc and kadmind in MIT Kerberos 5 (krb5) 1.4 through 1.6.3 allows remote attackers to execute arbitr…EPSS 8.8%10.0CVE-2007-5902Mit kerberos 5 vulnerabilityInteger overflow in the svcauth_gss_get_principal function in lib/rpc/svc_auth_gss.c in MIT Kerberos 5 (krb5) allows remote attackers to have an unkn…EPSS 5.9%10.0CVE-2007-4743Mit kerberos 5 memory buffer overflow vulnerabilityThe original patch for CVE-2007-3999 in svc_auth_gss.c in the RPCSEC_GSS RPC library in MIT Kerberos 5 (krb5) 1.4 through 1.6.2, as used by the Kerbe…EPSS 4.6%10.0CVE-2007-2442Mit kerberos 5 vulnerabilityThe gssrpc__svcauth_gssapi function in the RPC library in MIT Kerberos 5 (krb5) 1.6.1 and earlier might allow remote attackers to execute arbitrary c…EPSS 11%10.0CVE-2007-0956Mit kerberos 5 missing authentication for critical function vulnerabilityThe telnet daemon (telnetd) in MIT krb5 before 1.6.1 allows remote attackers to bypass authentication and gain system access via a username beginning…EPSS 30%

Source: NIST National Vulnerability Database (record CVE-2007-3999), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.