Red Hat Inc. Information for VU#795632
MIT Kerberos 5 ASN.1 decoding functions insecurely deallocate memory (double-free)
- Vendor Information Help Date Notified: 21 Jul 2004
- Statement Date:
- Date Updated: 02 Sep 2004
New krb5 packages are now available along with our advisory at the URLs below and by using the Red Hat Network 'up2date' tool. Please note that Red Hat Enterprise Linux 3 contained a fix for VU#350792 (CAN-2004-0772) from release, and for Red Hat Enterprise Linux 2.1 users this issue was fixed in a previous update, RHSA-2003:052.
The vendor has not provided us with any further information regarding this vulnerability.
The CERT/CC has no additional comments at this time.
If you have feedback, comments, or additional information about this vulnerability, please send us email.