Double free vulnerability in the GSS-API library (lib/gssapi/krb5/k5unseal.c), as used by the Kerberos administration daemon (kadmind) in MIT krb5 before 1.6.1, when used with the authentication method provided by the RPCSEC_GSS RPC library, allows remote authenticated users to execute arbitrary code and modify the Kerberos key database via a message with an "an invalid direction encoding".
Metrics
Affected Vendors & Products
Advisories
Source | ID | Title |
---|---|---|
![]() |
DSA-1276-1 | New krb5 packages fix several vulnerabilities |
![]() |
USN-449-1 | krb5 vulnerabilities |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.

Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-07T12:50:34.980Z
Reserved: 2007-03-02T00:00:00
Link: CVE-2007-1216

No data.

Status : Deferred
Published: 2007-04-06T01:19:00.000
Modified: 2025-04-09T00:30:58.490
Link: CVE-2007-1216


No data.