Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-f6c2-j3p8-vxvv

Опубликовано: 01 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

KDC in MIT Kerberos 5 (krb5kdc) does not set a global variable for some krb4 message types, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted messages that trigger a NULL pointer dereference or double-free.

KDC in MIT Kerberos 5 (krb5kdc) does not set a global variable for some krb4 message types, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted messages that trigger a NULL pointer dereference or double-free.

Ссылки

EPSS

Процентиль: 91%
0.07232
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-665

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 17 лет назад

KDC in MIT Kerberos 5 (krb5kdc) does not set a global variable for some krb4 message types, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted messages that trigger a NULL pointer dereference or double-free.

redhat
больше 17 лет назад

KDC in MIT Kerberos 5 (krb5kdc) does not set a global variable for some krb4 message types, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted messages that trigger a NULL pointer dereference or double-free.

CVSS3: 9.8
nvd
больше 17 лет назад

KDC in MIT Kerberos 5 (krb5kdc) does not set a global variable for some krb4 message types, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted messages that trigger a NULL pointer dereference or double-free.

CVSS3: 9.8
debian
больше 17 лет назад

KDC in MIT Kerberos 5 (krb5kdc) does not set a global variable for som ...

fstec
больше 17 лет назад

Уязвимости операционной системы Red Hat Enterprise Linux, позволяющие удаленному злоумышленнику нарушить конфиденциальность, целостность и доступность защищаемой информации

EPSS

Процентиль: 91%
0.07232
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-665