CVE-2023-39975
krb5: double-free in KDC TGS processing
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
kdc/do_tgs_req.c in MIT Kerberos 5 (aka krb5) 1.21 before 1.21.2 has a double free that is reachable if an authenticated user can trigger an authorization-data handling failure. Incorrect data is copied from one ticket to another.
kdc/do_tgs_req.c en MIT Kerberos 5 (también conocido como krb5) 1.21 antes de 1.21.2 tiene un double free que es accesible si un usuario autenticado puede desencadenar un error de gestión de datos de autorización. Los datos incorrectos se copian de un ticket a otro.
A vulnerability was found in MIT krb5, where an authenticated attacker can cause a KDC to free the same pointer twice if it can induce a failure in authorization data handling.
Multiple vulnerabilities have been discovered in MIT krb5, the worst of which could lead to remote code execution. Versions greater than or equal to 1.21.2 are affected.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2023-08-07 CVE Reserved
- 2023-08-16 CVE Published
- 2024-08-02 CVE Updated
- 2025-07-28 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-415: Double Free
CAPEC
References (8)
URL | Tag | Source |
---|---|---|
https://security.netapp.com/advisory/ntap-20230915-0014 |
|
|
https://security.netapp.com/advisory/ntap-20240201-0005 |
|
|
https://security.netapp.com/advisory/ntap-20240201-0008 |
|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://github.com/krb5/krb5/commit/88a1701b423c13991a8064feeb26952d3641d840 | 2024-02-01 | |
https://github.com/krb5/krb5/compare/krb5-1.21.1-final...krb5-1.21.2-final | 2024-02-01 |
URL | Date | SRC |
---|---|---|
https://web.mit.edu/kerberos/www/advisories | 2024-02-01 | |
https://access.redhat.com/security/cve/CVE-2023-39975 | 2023-11-07 | |
https://bugzilla.redhat.com/show_bug.cgi?id=2232682 | 2023-11-07 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Mit Search vendor "Mit" | Kerberos 5 Search vendor "Mit" for product "Kerberos 5" | >= 1.21 < 1.21.2 Search vendor "Mit" for product "Kerberos 5" and version " >= 1.21 < 1.21.2" | - |
Affected
|