CVE-2023-39975: Double Free
Published Aug 16, 2023
·Updated
kdc/dotgsreq.c in MIT Kerberos 5 (aka krb5) 1.21 before 1.21.2 has a double free that is reachable if an authenticated user can trigger an authorization-data handling failure. Incorrect data is copied from one ticket to another.
Affected Software
1 affected component
MIT Kerberos 5>=1.21<1.21.2
Remediation
Event History
Aug 16, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·03:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID of this vulnerability?
The vulnerability ID is CVE-2023-39975.
2
What is the severity of CVE-2023-39975?
The severity of CVE-2023-39975 is high, with a CVSS score of 8.8.
3
What software is affected by CVE-2023-39975?
MIT Kerberos 5 versions 1.21 before 1.21.2 are affected by CVE-2023-39975.
4
How can an attacker exploit CVE-2023-39975?
An authenticated user can trigger an authorization-data handling failure to exploit CVE-2023-39975.
5
Is there a fix available for CVE-2023-39975?
Yes, a fix is available in MIT Kerberos 5 version 1.21.2.