CVE Vulnerabilities

CVE-2017-11462

Double Free

Published: Sep 13, 2017 | Modified: Apr 20, 2025
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
3.7 LOW
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
Ubuntu
LOW
root.io logo minimus.io logo echo.ai logo

Double free vulnerability in MIT Kerberos 5 (aka krb5) allows attackers to have unspecified impact via vectors involving automatic deletion of security contexts on error.

Weakness

The product calls free() twice on the same memory address.

Affected Software

NameVendorStart VersionEnd Version
Kerberos_5Mit1.14 (including)1.14 (including)
Kerberos_5Mit1.14-alpha1 (including)1.14-alpha1 (including)
Kerberos_5Mit1.14-beta1 (including)1.14-beta1 (including)
Kerberos_5Mit1.14-beta2 (including)1.14-beta2 (including)
Kerberos_5Mit1.14.1 (including)1.14.1 (including)
Kerberos_5Mit1.14.2 (including)1.14.2 (including)
Kerberos_5Mit1.14.3 (including)1.14.3 (including)
Kerberos_5Mit1.14.4 (including)1.14.4 (including)
Kerberos_5Mit1.14.5 (including)1.14.5 (including)
Kerberos_5Mit1.15 (including)1.15 (including)
Kerberos_5Mit1.15.1 (including)1.15.1 (including)
Kerberos_5Mit1.15.1-beta1 (including)1.15.1-beta1 (including)
Kerberos_5Mit1.15.1-beta2 (including)1.15.1-beta2 (including)
Krb5Ubuntuartful*
Krb5Ubuntuesm-infra-legacy/trusty*
Krb5Ubuntuesm-infra/xenial*
Krb5Ubuntuprecise/esm*
Krb5Ubuntutrusty*
Krb5Ubuntutrusty/esm*
Krb5Ubuntuvivid/ubuntu-core*
Krb5Ubuntuxenial*
Krb5Ubuntuzesty*

Potential Mitigations

References