Unrated severityNVD Advisory· Published Apr 22, 2010· Updated Apr 29, 2026
CVE-2010-1320
CVE-2010-1320
Description
Double free vulnerability in do_tgs_req.c in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.7.x and 1.8.x before 1.8.2 allows remote authenticated users to cause a denial of service (daemon crash) or possibly execute arbitrary code via a request associated with (1) renewal or (2) validation.
Affected products
4cpe:2.3:a:mit:kerberos_5:1.7:*:*:*:*:*:*:*+ 3 more
- cpe:2.3:a:mit:kerberos_5:1.7:*:*:*:*:*:*:*
- cpe:2.3:a:mit:kerberos_5:1.7.1:*:*:*:*:*:*:*
- cpe:2.3:a:mit:kerberos_5:1.8:*:*:*:*:*:*:*
- cpe:2.3:a:mit:kerberos_5:1.8.1:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
15- www.securityfocus.com/bid/39599nvdExploit
- bugs.debian.org/cgi-bin/bugreport.cginvd
- lists.apple.com/archives/security-announce/2010//Jun/msg00001.htmlnvd
- lists.opensuse.org/opensuse-security-announce/2010-04/msg00006.htmlnvd
- secunia.com/advisories/39656nvd
- secunia.com/advisories/39784nvd
- secunia.com/advisories/40220nvd
- securitytracker.com/idnvd
- support.apple.com/kb/HT4188nvd
- web.mit.edu/kerberos/advisories/MITKRB5-SA-2010-004.txtnvd
- www.securityfocus.com/archive/1/510843/100/0/threadednvd
- www.ubuntu.com/usn/USN-940-1nvd
- www.vupen.com/english/advisories/2010/1001nvd
- www.vupen.com/english/advisories/2010/1192nvd
- www.vupen.com/english/advisories/2010/1481nvd
News mentions
0No linked articles in our index yet.