Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).
Severity
4.0MEDIUMNVD
EPSS
22.1%
top 4.20%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Affected products
Timeline
PublishedApr 22
Latest updateMay 2

Description

Double free vulnerability in do_tgs_req.c in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.7.x and 1.8.x before 1.8.2 allows remote authenticated users to cause a denial of service (daemon crash) or possibly execute arbitrary code via a request associated with (1) renewal or (2) validation.

CVSS vector

AV:N/AC:L/C:N/I:N/A:PExploitability: 8.0 | Impact: 2.9

Affected Packages2 packages

Debianmit/krb5< 1.8.1+dfsg-2+3
NVDmit/kerberos_54 versions+3

🔴Vulnerability Details

3
GHSA
GHSA-xrh6-gg74-rf7v: Double free vulnerability in do_tgs_req2022-05-02
OSV
CVE-2010-1320: Double free vulnerability in do_tgs_req2010-04-22
CVEList
CVE-2010-1320: Double free vulnerability in do_tgs_req2010-04-22

💥Exploits & PoCs

2
Exploit-DB
Network Associates PGP KeyServer 7 - LDAP Buffer Overflow (Metasploit)2010-11-14
Exploit-DB
MIT Kerberos 5 - 'src/kdc/do_tgs_req.c' Ticket Renewal Double-Free Memory Corruption2010-04-20

📋Vendor Advisories

3
Ubuntu
Kerberos vulnerabilities2010-05-19
Red Hat
krb5: double-free vulnerability in 1.7+2010-04-20
Debian
CVE-2010-1320: krb5 - Double free vulnerability in do_tgs_req.c in the Key Distribution Center (KDC) i...2010

💬Community

4
Bugzilla
CVE-2011-0284 krb5 (krb5kdc): Double-free flaw by handling error messages upon receiving certain AS_REQ's (MITKRB5-SA-2011-003)2011-02-01
Bugzilla
CVE-2010-1320 krb5: double-free vulnerability in 1.7+ [fedora-13]2010-04-20
Bugzilla
CVE-2010-1320 krb5: double-free vulnerability in 1.7+ [fedora-12]2010-04-20
Bugzilla
CVE-2010-1320 krb5: double-free vulnerability in 1.7+2010-04-13
CVE-2010-1320 — Use After Free in MIT Kerberos 5 | cvebase