CVSS2
Attack Vector
NETWORK
Attack Complexity
MEDIUM
Authentication
SINGLE
Confidentiality Impact
COMPLETE
Integrity Impact
COMPLETE
Availability Impact
COMPLETE
AV:N/AC:M/Au:S/C:C/I:C/A:C
EPSS
Percentile
97.1%
The kadm5_modify_policy_internal function in lib/kadm5/srv/svr_policy.c in
the Kerberos administration daemon (kadmind) in MIT Kerberos 5 (krb5) 1.5
through 1.6.2 does not properly check return values when the policy does
not exist, which might allow remote authenticated users with the βmodify
policyβ privilege to execute arbitrary code via unspecified vectors that
trigger a write to an uninitialized pointer.