CVE-2007-5972

Severity CVSS v4.0:
Pending analysis
Type:
CWE-119 Buffer Errors
Publication date:
06/12/2007
Last modified:
09/04/2025

Description

Double free vulnerability in the krb5_def_store_mkey function in lib/kdb/kdb_default.c in MIT Kerberos 5 (krb5) 1.5 has unknown impact and remote authenticated attack vectors. NOTE: the free operations occur in code that stores the krb5kdc master key, and so the attacker must have privileges to store this key.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:mit:kerberos_5:1.5:*:*:*:*:*:*:*