vulnerability

Red Hat: CVE-2023-39975: double-free in KDC TGS processing (Multiple Advisories)

Severity
9
CVSS
(AV:N/AC:L/Au:S/C:C/I:C/A:C)
Published
Aug 16, 2023
Added
Nov 8, 2023
Modified
Jan 28, 2025

Description

kdc/do_tgs_req.c in MIT Kerberos 5 (aka krb5) 1.21 before 1.21.2 has a double free that is reachable if an authenticated user can trigger an authorization-data handling failure. Incorrect data is copied from one ticket to another.

Solution(s)

redhat-upgrade-krb5-debuginforedhat-upgrade-krb5-debugsourceredhat-upgrade-krb5-develredhat-upgrade-krb5-libsredhat-upgrade-krb5-libs-debuginforedhat-upgrade-krb5-pkinitredhat-upgrade-krb5-pkinit-debuginforedhat-upgrade-krb5-serverredhat-upgrade-krb5-server-debuginforedhat-upgrade-krb5-server-ldapredhat-upgrade-krb5-server-ldap-debuginforedhat-upgrade-krb5-workstationredhat-upgrade-krb5-workstation-debuginforedhat-upgrade-libkadm5redhat-upgrade-libkadm5-debuginfo
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.