Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2007-3999

33
FAUCET Score

CVE-2007-3999 describes a critical stack-based buffer overflow vulnerability in the svcauth_gss_validate function within the RPCSEC_GSS RPC library (librpcsecgss) of MIT Kerberos 5 (krb5) versions 1.4 through 1.6.2. This flaw, affecting the Kerberos administration daemon (kadmind) and other krb5-dependent applications, allows remote attackers to trigger a denial of service and potentially execute arbitrary code by sending a crafted, long string in an RPC message. With a CVSS score of 10.0, this vulnerability is highly severe, requiring no authentication and having low attack complexity, leading to complete compromise of confidentiality, integrity, and availability. Despite its high severity, there is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
1.4CPE matchmatch criteria
cpe:2.3:a:mit:kerberos_5:1.4:*:*:*:*:*:*:*
1.4.1CPE matchmatch criteria
cpe:2.3:a:mit:kerberos_5:1.4.1:*:*:*:*:*:*:*
1.4.2CPE matchmatch criteria
cpe:2.3:a:mit:kerberos_5:1.4.2:*:*:*:*:*:*:*
1.4.3CPE matchmatch criteria
cpe:2.3:a:mit:kerberos_5:1.4.3:*:*:*:*:*:*:*
1.4.4CPE matchmatch criteria
cpe:2.3:a:mit:kerberos_5:1.4.4:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 2.0

10.0HIGH

AV:N/AC:L/Au:N/C:C/I:C/A:C

Confidentiality Impact
COMPLETE
Integrity Impact
COMPLETE
Availability Impact
COMPLETE
Access Vector
NETWORK
Access Complexity
LOW
Authentication
NONE
Exploitability Score
10.0
Impact Score
10.0
CvssVersion
2.0

Exploit Intelligence

EPSS Score
11.00%
Probability of exploitation in next 30 days
EPSS Percentile
95.4%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.1100 is in the 93rd percentile among its peer group of 51,551 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (7)

redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 4Fixed in: nfs-utils-lib-0:1.0.6-8.z1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 5Fixed in: krb5-0:1.5-29
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 5Fixed in: nfs-utils-lib-0:1.0.8-7.2.z2
View patch
fuji_electricvendor investigatingvia llm_extracted
langgeniusvendor investigatingvia llm_extracted
lizardbytevendor investigatingvia llm_extracted
opensipsvendor investigatingvia llm_extracted

Vendor Advisories (5)

redhatCVE-2007-3999Important

krb5 RPC library buffer overflow

Sep 4, 2007
langgeniusllm-langgenius-41ab4291fd4937f1CRITICAL

MIT Kerberos 5 RPCSEC_GSS RPC Library (librpcsecgss) lib/rpc/svc_auth_gss.c svcauth_gss_validate Function Remote Overflow

Sep 4, 2007
lizardbytellm-lizardbyte-6fdb923bc15fafd2CRITICAL

MIT Kerberos 5 RPCSEC_GSS RPC Library (librpcsecgss) lib/rpc/svc_auth_gss.c svcauth_gss_validate Function Remote Overflow

Sep 4, 2007
opensipsllm-opensips-3f945caa76b36a16CRITICAL

MIT Kerberos 5 RPCSEC_GSS RPC Library (librpcsecgss) lib/rpc/svc_auth_gss.c svcauth_gss_validate Function Remote Overflow

Sep 4, 2007
fuji_electricllm-fuji_electric-5d8b48391cf36e6fCRITICAL

MIT Kerberos 5 RPCSEC_GSS RPC Library (librpcsecgss) lib/rpc/svc_auth_gss.c svcauth_gss_validate Function Remote Overflow

Sep 4, 2007

References

docs.info.apple.com / article.html
lists.apple.com / archives/security-announce/2007/Nov/msg00002.html
lists.rpath.com / pipermail/security-announce/2007-September/000237.html
bugzilla.redhat.com / show_bug.cgi
secunia.com / advisories/26676
Vendor Advisory
secunia.com / advisories/26680
Vendor Advisory
secunia.com / advisories/26684
Vendor Advisory
secunia.com / advisories/26691
Vendor Advisory
secunia.com / advisories/26697
Vendor Advisory
secunia.com / advisories/26699
Vendor Advisory
secunia.com / advisories/26700
Vendor Advisory
secunia.com / advisories/26705
Vendor Advisory
secunia.com / advisories/26713
Vendor Advisory
secunia.com / advisories/26728
Vendor Advisory
secunia.com / advisories/26783
Vendor Advisory
secunia.com / advisories/26792
Vendor Advisory
secunia.com / advisories/26822
Vendor Advisory
secunia.com / advisories/26896
Vendor Advisory
secunia.com / advisories/26987
Vendor Advisory
secunia.com / advisories/27043
Vendor Advisory
secunia.com / advisories/27081
Vendor Advisory
secunia.com / advisories/27146
Vendor Advisory
secunia.com / advisories/27643
Vendor Advisory
secunia.com / advisories/27756
secunia.com / advisories/29247
secunia.com / advisories/29270
security.gentoo.org / glsa/glsa-200710-01.xml
securityreason.com / securityalert/3092
exchange.xforce.ibmcloud.com / vulnerabilities/36437
oval.cisecurity.org / repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A3162
oval.cisecurity.org / repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9379
sunsolve.sun.com / search/document.do
sunsolve.sun.com / search/document.do
support.avaya.com / elmodocs2/security/ASA-2007-396.htm
redhat.com / archives/fedora-package-announce/2007-September/msg00087.html
redhat.com / archives/fedora-package-announce/2008-March/msg00173.html
web.mit.edu / Kerberos/advisories/MITKRB5-SA-2007-006.txt
debian.org / security/2007/dsa-1367
debian.org / security/2007/dsa-1368
gentoo.org / security/en/glsa/glsa-200709-01.xml
kb.cert.org / vuls/id/883632
US Government Resource
mandriva.com / security/advisories
mandriva.com / security/advisories
novell.com / linux/security/advisories/2007_19_sr.html
novell.com / linux/security/advisories/2007_24_sr.html
redhat.com / support/errata/RHSA-2007-0858.html
redhat.com / support/errata/RHSA-2007-0913.html
redhat.com / support/errata/RHSA-2007-0951.html
securityfocus.com / archive/1/478748/100/0/threaded
securityfocus.com / archive/1/479251/100/0/threaded
securityfocus.com / bid/25534
securityfocus.com / bid/26444
securitytracker.com / id
trustix.org / errata/2007/0026
ubuntu.com / usn/usn-511-1
us-cert.gov / cas/techalerts/TA07-319A.html
US Government Resource
vupen.com / english/advisories/2007/3051
vupen.com / english/advisories/2007/3052
vupen.com / english/advisories/2007/3060
vupen.com / english/advisories/2007/3868
vupen.com / english/advisories/2008/0803/references
zerodayinitiative.com / advisories/ZDI-07-052.html