CVE-2010-1320
MEDIUM 4.0EPSS 11.9%
Double free vulnerability in do_tgs_req.c in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.7.x and 1.8.x before 1.8.2 allows remote authenticated users to cause a denial of service (daemon crash) or possibly execute arbitrary code via a request associated with (1) renewal or (2) validation.
- CVSS v2.0
- 4.0 MEDIUM
AV:N/AC:L/Au:S/C:N/I:N/A:P - EPSS
- 11.86% chance of exploitation in the next 30 days, 96th percentile
- Published
- 2010-04-22
- Updated
- 2024-08-07