CVE-2011-0284 is a double free vulnerability in the Key Distribution Center (KDC) of MIT Kerberos 5 versions 1.7 through 1.9, specifically within the prepare_error_as function when the PKINIT feature is enabled. This flaw allows remote attackers to trigger a denial of service by crashing the daemon, and potentially execute arbitrary code, via crafted typed data in the e_data field. With a CVSS score of 7.6, it is considered highly severe due to its network-based attack vector, high impact on confidentiality, integrity, and availability, despite requiring high attack complexity. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage for this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.7CPE matchmatch criteria | cpe:2.3:a:mit:kerberos_5:1.7:*:*:*:*:*:*:* | ||
1.7.1CPE matchmatch criteria | cpe:2.3:a:mit:kerberos_5:1.7.1:*:*:*:*:*:*:* | ||
1.8CPE matchmatch criteria | cpe:2.3:a:mit:kerberos_5:1.8:*:*:*:*:*:*:* | ||
1.8.1CPE matchmatch criteria | cpe:2.3:a:mit:kerberos_5:1.8.1:*:*:*:*:*:*:* | ||
1.8.2CPE matchmatch criteria | cpe:2.3:a:mit:kerberos_5:1.8.2:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:H/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.