Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-39975

Опубликовано: 16 авг. 2023
Источник: redhat
CVSS3: 8.8
EPSS Низкий

Описание

kdc/do_tgs_req.c in MIT Kerberos 5 (aka krb5) 1.21 before 1.21.2 has a double free that is reachable if an authenticated user can trigger an authorization-data handling failure. Incorrect data is copied from one ticket to another.

A vulnerability was found in MIT krb5, where an authenticated attacker can cause a KDC to free the same pointer twice if it can induce a failure in authorization data handling.

Отчет

This vulnerability is rated as an Important because a double-free vulnerability was found in krb5 KDC within the TGS processing logic. The flaw is triggered when an authenticated attacker sends a TGS renew or validate request that induces a failure in authorization data handling. This action causes the same memory pointer to be freed twice, leading to a crash, successful exploitation could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS).

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6krb5Not affected
Red Hat Enterprise Linux 7krb5Not affected
Red Hat Enterprise Linux 8krb5Not affected
Red Hat Enterprise Linux 9krb5FixedRHSA-2023:669907.11.2023
Red Hat Enterprise Linux 9krb5FixedRHSA-2023:669907.11.2023

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-415
https://bugzilla.redhat.com/show_bug.cgi?id=2232682krb5: double-free in KDC TGS processing

EPSS

Процентиль: 66%
0.01229
Низкий

8.8 High

CVSS3

Связанные уязвимости

CVSS3: 8.8
ubuntu
почти 3 года назад

kdc/do_tgs_req.c in MIT Kerberos 5 (aka krb5) 1.21 before 1.21.2 has a double free that is reachable if an authenticated user can trigger an authorization-data handling failure. Incorrect data is copied from one ticket to another.

CVSS3: 8.8
nvd
почти 3 года назад

kdc/do_tgs_req.c in MIT Kerberos 5 (aka krb5) 1.21 before 1.21.2 has a double free that is reachable if an authenticated user can trigger an authorization-data handling failure. Incorrect data is copied from one ticket to another.

CVSS3: 8.8
debian
почти 3 года назад

kdc/do_tgs_req.c in MIT Kerberos 5 (aka krb5) 1.21 before 1.21.2 has a ...

CVSS3: 8.8
github
почти 3 года назад

kdc/do_tgs_req.c in MIT Kerberos 5 (aka krb5) 1.21 before 1.21.2 has a double free that is reachable if an authenticated user can trigger an authorization-data handling failure. Incorrect data is copied from one ticket to another.

rocky
2 месяца назад

Moderate: krb5 security and bug fix update

EPSS

Процентиль: 66%
0.01229
Низкий

8.8 High

CVSS3