Use-after-free vulnerability in kadmin/server...
Moderate severity
Unreviewed
Published
May 2, 2022
to the GitHub Advisory Database
•
Updated Feb 2, 2024
Description
Published by the National Vulnerability Database
Apr 7, 2010
Published to the GitHub Advisory Database
May 2, 2022
Last updated
Feb 2, 2024
Use-after-free vulnerability in kadmin/server/server_stubs.c in kadmind in MIT Kerberos 5 (aka krb5) 1.5 through 1.6.3 allows remote authenticated users to cause a denial of service (daemon crash) via a request from a kadmin client that sends an invalid API version number.
References