CVE-2023-39975
krb5: double-free in KDC TGS processing
Severity Score
8.8
*CVSS v3.1
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
kdc/do_tgs_req.c in MIT Kerberos 5 (aka krb5) 1.21 before 1.21.2 has a double free that is reachable if an authenticated user can trigger an authorization-data handling failure. Incorrect data is copied from one ticket to another.
kdc/do_tgs_req.c en MIT Kerberos 5 (también conocido como krb5) 1.21 antes de 1.21.2 tiene un double free que es accesible si un usuario autenticado puede desencadenar un error de gestión de datos de autorización. Los datos incorrectos se copian de un ticket a otro.
A vulnerability was found in MIT krb5, where an authenticated attacker can cause a KDC to free the same pointer twice if it can induce a failure in authorization data handling.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2023-08-07 CVE Reserved
- 2023-08-16 CVE Published
- 2024-08-02 CVE Updated
- 2024-11-20 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-415: Double Free
CAPEC
References (8)
URL | Tag | Source |
---|---|---|
https://security.netapp.com/advisory/ntap-20230915-0014 | ||
https://security.netapp.com/advisory/ntap-20240201-0005 | ||
https://security.netapp.com/advisory/ntap-20240201-0008 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://github.com/krb5/krb5/commit/88a1701b423c13991a8064feeb26952d3641d840 | 2024-02-01 | |
https://github.com/krb5/krb5/compare/krb5-1.21.1-final...krb5-1.21.2-final | 2024-02-01 |
URL | Date | SRC |
---|---|---|
https://web.mit.edu/kerberos/www/advisories | 2024-02-01 | |
https://access.redhat.com/security/cve/CVE-2023-39975 | 2023-11-07 | |
https://bugzilla.redhat.com/show_bug.cgi?id=2232682 | 2023-11-07 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Mit Search vendor "Mit" | Kerberos 5 Search vendor "Mit" for product "Kerberos 5" | >= 1.21 < 1.21.2 Search vendor "Mit" for product "Kerberos 5" and version " >= 1.21 < 1.21.2" | - |
Affected
|