AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2011-0285

HIGH · CVSS 10 EPSS 20.77%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2011-04-15 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2011-0285
Severity
HIGH
CVSS
10
EPSS
20.77%

Original NVD Description

The process_chpw_request function in schpw.c in the password-changing functionality in kadmind in MIT Kerberos 5 (aka krb5) 1.7 through 1.9 frees an invalid pointer, which allows remote attackers to execute arbitrary code or cause a denial of service (daemon crash) via a crafted request that triggers an error condition.