Bugzilla – Bug 1218211
VUL-0: CVE-2023-39975: krb5: double-free in KDC TGS processing
Last modified: 2024-05-27 14:40:05 UTC
kdc/do_tgs_req.c in MIT Kerberos 5 (aka krb5) 1.21 before 1.21.2 has a double free that is reachable if an authenticated user can trigger an authorization-data handling failure. Incorrect data is copied from one ticket to another. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-39975
This is only affecting Factory. openSUSE:Factory krb5 v1.21.1
submitted for factory
This is an autogenerated message for OBS integration: This bug (1218211) was mentioned in https://build.opensuse.org/request/show/1134351 Factory / krb5