Double free vulnerability in the GSS-API library (lib/gssapi/krb5/k5unseal.c), as used by the Kerberos administration daemon (kadmind) in MIT krb5 before 1.6.1, when used with the authentication method provided by the RPCSEC_GSS RPC library, allows remote authenticated users to execute arbitrary code and modify the Kerberos key database via a message with an "an invalid direction encoding".
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2007-04-06T01:00:00
Updated: 2024-08-07T12:50:34.980Z
Reserved: 2007-03-02T00:00:00
Link: CVE-2007-1216
Vulnrichment
No data.
NVD
Status : Analyzed
Published: 2007-04-06T01:19:00.000
Modified: 2021-02-02T18:22:26.620
Link: CVE-2007-1216
Redhat