Back

HIGH

krb5: double free in kdb lib

Published Dec 6, 2007

Description

Double free vulnerability in the krb5_def_store_mkey function in lib/kdb/kdb_default.c in MIT Kerberos 5 (krb5) 1.5 has unknown impact and remote authenticated attack vectors. NOTE: the free operations occur in code that stores the krb5kdc master key, and so the attacker must have privileges to store this key.

Affected products

Remediation

Red Hat statement

This issue is not a vulnerability, for more information see https://marc.info/?m=119743235325151

Metrics

References (17)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Dec 6, 2007
Updated Aug 7, 2024
Reserved Nov 14, 2007
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Low
Public date Nov 14, 2007