OpenPKG Security Advisory – According to vendor security advisories, two security issues exist in the Kerberos network authentication system implementation MIT Kerberos. First, the RPC library could call an uninitialized function pointer, which created a security vulnerability for kadmind(8). Second, the GSS-API “mechglue” layer could fail to initialize some output pointers, causing callers to attempt to free uninitialized pointers. This caused another security vulnerability in kadmind(8).
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/53587/OpenPKG-SA-2007.006.txt
Source: https://packetstormsecurity.com/files/53587/OpenPKG-Security-Advisory-2007.6.html

