Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Double free vulnerability in the init_ctx_reselect function in the SPNEGO initiator in lib/gssapi/spnego/spnego_mech.c in MIT Kerberos 5 (aka krb5) 1.10.x through 1.12.x before 1.12.2 allows remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via network traffic that appears to come from an intended acceptor, but specifies a security mechanism different from the one proposed by the initiator.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
MIT Kerberos 5 双重释放漏洞
Vulnerability Description
MIT Kerberos 5(又名krb5)是美国麻省理工学院(MIT)开发的一套网络认证协议,它采用客户端/服务器结构,并且客户端和服务器端均可对对方进行身份认证(即双重验证),可防止窃听、防止replay攻击等。 MIT krb5 1.12.2之前1.10.x至1.12.x版本中lib/gssapi/spnego/spnego_mech.c文件的SPNEGO启动器的‘init_ctx_reselect’函数中存在双重释放漏洞,该漏洞源于程序在接收来自既定接收器的数据包时没有对其安全机制进行检查。远程攻
CVSS Information
N/A
Vulnerability Type
N/A