← All CVEs

CVE-2011-0285

high · 10

The process_chpw_request function in schpw.c in the password-changing functionality in kadmind in MIT Kerberos 5 (aka krb5) 1.7 through 1.9 frees an invalid pointer, which allows remote attackers to execute arbitrary code or cause a denial of service (daemon crash) via a crafted request that triggers an error condition.

10
CVSS
20.8%
EPSS (exploit prob.)
97th
EPSS percentile
2011-04-15
Published

AV:N/AC:L/Au:N/C:C/I:C/A:C

Weaknesses

CWE-20

Affected products

VendorProductAffected versions
mitkerberos_51.7
mitkerberos_51.7.1
mitkerberos_51.8
mitkerberos_51.8.1
mitkerberos_51.8.2
mitkerberos_51.8.3
mitkerberos_51.9

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2011-0285