Back

CVE-2005-1689

CRITICAL

Double free vulnerability in the krb5_recvauth function in MIT Kerberos 5 (krb5) 1.4.1 and earlier allows remote attackers to execute arbitrary code via certain error conditions.

Published: Jul 18, 2005 Modified: Jun 16, 2026
CWE-415

CVSS Metrics

CVSSv3
Attack Vector: NETWORK Attack Complexity: LOW Privileges Required: NONE User Interaction: NONE Scope: UNCHANGED Confidentiality Impact: HIGH Integrity Impact: HIGH Availability Impact: HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Products (5)

Vendor Product Version
mit kerberos_5 *
apple mac_os_x * < 10.4.2
apple mac_os_x_server * < 10.4.2
debian debian_linux 3.0
debian debian_linux 3.1

GitHub Security Advisory GHSA-8mfg-j523-2x92

Double free vulnerability in the krb5_recvauth function in MIT Kerberos 5 (krb5) 1.4.1 and...

Risk Scores

CVSS Score 9.8 / 10
EPSS Score 11.01%

Top 4% most likely to be exploited

Threat Score 42.5 / 100

Data Sources

NVD EPSS GitHub