CVE-2004-0642Double Free in Kerberos 5

CWE-415Double Free9 documents8 sources
Severity
7.5HIGHNVD
EPSS
25.8%
top 3.74%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 28
Latest updateApr 29

Description

Double free vulnerabilities in the error handling code for ASN.1 decoders in the (1) Key Distribution Center (KDC) library and (2) client library for MIT Kerberos 5 (krb5) 1.3.4 and earlier may allow remote attackers to execute arbitrary code.

CVSS vector

AV:N/AC:L/C:P/I:P/A:PExploitability: 10.0 | Impact: 6.4

Affected Packages5 packages

Also affects: Debian Linux 3.0

Patches

🔴Vulnerability Details

3
GHSA
GHSA-9vx5-gccr-9gr3: Double free vulnerabilities in the error handling code for ASN2022-04-29
OSV
CVE-2004-0642: Double free vulnerabilities in the error handling code for ASN2004-09-28
CVEList
CVE-2004-0642: Double free vulnerabilities in the error handling code for ASN2004-09-10

📋Vendor Advisories

3
Red Hat
security flaw2004-08-31
Cisco
Vulnerabilities in Kerberos 5 Implementation2004-08-31
Debian
CVE-2004-0642: krb5 - Double free vulnerabilities in the error handling code for ASN.1 decoders in the...2004

💬Community

1
Bugzilla
CVE-2004-0642 security flaw2018-08-16
CVE-2004-0642 — Double Free in MIT Kerberos 5 | cvebase