CVE-2004-0643Double Free in Kerberos 5

CWE-415Double Free10 documents9 sources
Severity
4.6MEDIUMNVD
EPSS
0.1%
top 67.17%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 28
Latest updateApr 29

Description

Double free vulnerability in the krb5_rd_cred function for MIT Kerberos 5 (krb5) 1.3.1 and earlier may allow local users to execute arbitrary code.

CVSS vector

AV:L/AC:L/C:P/I:P/A:PExploitability: 3.9 | Impact: 6.4

Affected Packages5 packages

Also affects: Debian Linux 3.0

Patches

🔴Vulnerability Details

3
GHSA
GHSA-2288-xjpv-v6jh: Double free vulnerability in the krb5_rd_cred function for MIT Kerberos 5 (krb5) 12022-04-29
OSV
CVE-2004-0643: Double free vulnerability in the krb5_rd_cred function for MIT Kerberos 5 (krb5) 12004-09-28
CVEList
CVE-2004-0643: Double free vulnerability in the krb5_rd_cred function for MIT Kerberos 5 (krb5) 12004-09-10

💥Exploits & PoCs

1
Exploit-DB
LHA 1.x - Remote Buffer Overflow / Directory Traversal2004-04-30

📋Vendor Advisories

3
Red Hat
security flaw2004-08-31
Cisco
Vulnerabilities in Kerberos 5 Implementation2004-08-31
Debian
CVE-2004-0643: krb5 - Double free vulnerability in the krb5_rd_cred function for MIT Kerberos 5 (krb5)...2004

💬Community

1
Bugzilla
CVE-2004-0643 security flaw2018-08-16
CVE-2004-0643 — Double Free in MIT Kerberos 5 | cvebase