Double free vulnerability in the GSS-API library (lib/gssapi/krb5/k5unseal.c), as used by the Kerberos administration daemon (kadmind) in MIT krb5 before 1.6.1, when used with the authentication method provided by the RPCSEC_GSS RPC library, allows remote authenticated users to execute arbitrary code and modify the Kerberos key database via a message with an "an invalid direction encoding".
Metrics
Affected Vendors & Products
References
History
No history.

Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-07T12:50:34.980Z
Reserved: 2007-03-02T00:00:00
Link: CVE-2007-1216

No data.

Status : Deferred
Published: 2007-04-06T01:19:00.000
Modified: 2025-04-09T00:30:58.490
Link: CVE-2007-1216
