Back

HIGH

krb5: double-free flaw in SPNEGO initiators

Published Aug 14, 2014

Description

Double free vulnerability in the init_ctx_reselect function in the SPNEGO initiator in lib/gssapi/spnego/spnego_mech.c in MIT Kerberos 5 (aka krb5) 1.10.x through 1.12.x before 1.12.2 allows remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via network traffic that appears to come from an intended acceptor, but specifies a security mechanism different from the one proposed by the initiator.

Affected products

Remediation

Red Hat statement

This issue did not affect the version of krb5 as shipped with Red Hat Enterprise Linux 5.

References (22)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner mitre
Published Aug 14, 2014
Updated Aug 6, 2024
Reserved Jun 20, 2014

CISA Vulnrichment

No data

NVD

Status Modified
Modified Jun 17, 2026

Red Hat

Severity Low
Public date Jul 15, 2014
Bugzilla 1121876

ENISA EUVD

Assigner mitre
Published Aug 14, 2014
Updated Aug 6, 2024

GitHub

No data