CVE-2023-39975
Published: 16 August 2023
kdc/do_tgs_req.c in MIT Kerberos 5 (aka krb5) 1.21 before 1.21.2 has a double free that is reachable if an authenticated user can trigger an authorization-data handling failure. Incorrect data is copied from one ticket to another.
Notes
Author | Note |
---|---|
allenpthuang | All versions in the archives are < 1.21, hence not-affected. This CVE only affects 1.21.x. |
Priority
Status
Package | Release | Status |
---|---|---|
krb5 Launchpad, Ubuntu, Debian |
upstream |
Not vulnerable
(debian: Vulnerable code not present)
|
bionic |
Not vulnerable
(code not presnet)
|
|
focal |
Not vulnerable
(code not presnet)
|
|
jammy |
Not vulnerable
(code not presnet)
|
|
lunar |
Not vulnerable
(code not presnet)
|
|
trusty |
Not vulnerable
(code not presnet)
|
|
xenial |
Not vulnerable
(code not presnet)
|
|
Patches: upstream: https://github.com/krb5/krb5/commit/88a1701b423c13991a8064feeb26952d3641d840 |
Severity score breakdown
Parameter | Value |
---|---|
Base score | 8.8 |
Attack vector | Network |
Attack complexity | Low |
Privileges required | Low |
User interaction | None |
Scope | Unchanged |
Confidentiality | High |
Integrity impact | High |
Availability impact | High |
Vector | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |