CVE-2010-1320 is a double free vulnerability in the Key Distribution Center (KDC) of MIT Kerberos 5 versions 1.7.x and 1.8.x before 1.8.2. This flaw allows remote authenticated users to trigger a denial of service (daemon crash) or potentially execute arbitrary code through specially crafted ticket renewal or validation requests. The vulnerability has a CVSS score of 4.0, indicating a medium severity, with a low attack complexity and requiring authentication. Its primary impact is a denial of service, though arbitrary code execution is a possibility. While there is no evidence of active exploitation (not in KEV or Hot List), an exploit for this vulnerability is available on ExploitDB. Despite this, there is minimal community discussion or media coverage surrounding CVE-2010-1320.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.7CPE matchmatch criteria | cpe:2.3:a:mit:kerberos_5:1.7:*:*:*:*:*:*:* | ||
1.7.1CPE matchmatch criteria | cpe:2.3:a:mit:kerberos_5:1.7.1:*:*:*:*:*:*:* | ||
1.8CPE matchmatch criteria | cpe:2.3:a:mit:kerberos_5:1.8:*:*:*:*:*:*:* | ||
1.8.1CPE matchmatch criteria | cpe:2.3:a:mit:kerberos_5:1.8.1:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:S/C:N/I:N/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.