Lucene search

K
prionPRIOn knowledge basePRION:CVE-2023-39975
HistoryAug 16, 2023 - 3:15 p.m.

Double free

2023-08-1615:15:00
PRIOn knowledge base
www.prio-n.com
9
mit kerberos 5
double free
vulnerability
authorization-data
nvd

8.3 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

41.3%

kdc/do_tgs_req.c in MIT Kerberos 5 (aka krb5) 1.21 before 1.21.2 has a double free that is reachable if an authenticated user can trigger an authorization-data handling failure. Incorrect data is copied from one ticket to another.

CPENameOperatorVersion
kerberos_5ge1.21
kerberos_5lt1.21.2