CVE-2023-39975
Description
kdc/do_tgs_req.c in MIT Kerberos 5 (aka krb5) 1.21 before 1.21.2 has a double free that is reachable if an authenticated user can trigger an authorization-data handling failure. Incorrect data is copied from one ticket to another.
Related CPE's
Could not find any relations
References
CvssV3 impact
Could not find any metrics
CvssV2 impact
Could not find any metrics