CVE-2011-0285
HIGH 10.0EPSS 20.8%
The process_chpw_request function in schpw.c in the password-changing functionality in kadmind in MIT Kerberos 5 (aka krb5) 1.7 through 1.9 frees an invalid pointer, which allows remote attackers to execute arbitrary code or cause a denial of service (daemon crash) via a crafted request that triggers an error condition.
- CVSS v2.0
- 10.0 HIGH
AV:N/AC:L/Au:N/C:C/I:C/A:C - EPSS
- 20.77% chance of exploitation in the next 30 days, 97th percentile
- Published
- 2011-04-15
- Updated
- 2024-08-06