krb5: double-free flaw
| Package(s): | krb5 | CVE #(s): | CAN-2004-0175 CAN-2005-0488 CAN-2005-1175 CAN-2005-1689 | ||||||||||||||||||||||||||||||||||||||||
| Created: | July 12, 2005 | Updated: | December 6, 2005 | ||||||||||||||||||||||||||||||||||||||||
| Description: | The krb5 authentication has a double-free flaw which may be initiated by a remote unauthenticated attacker. Also, a single byte heap overflow in the krb5_unparse_name() function can lead to a denial of service and an information disclosure may be caused by a malicious telnet server. See This report for more information. | ||||||||||||||||||||||||||||||||||||||||||
| Alerts: |
| ||||||||||||||||||||||||||||||||||||||||||
