In MIT Kerberos 5 (aka krb5) before 1.21.3, an attacker can cause invalid memory reads during GSS message token handling by sending message tokens with invalid length fields.
References
Configurations
History
13 Mar 2025, 21:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
18 Sep 2024, 12:39
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:* cpe:2.3:o:debian:debian_linux:12.0:*:*:*:*:*:*:* |
|
First Time |
Debian
Debian debian Linux |
27 Aug 2024, 17:47
Type | Values Removed | Values Added |
---|---|---|
CWE | NVD-CWE-Other | |
First Time |
Mit kerberos 5
Mit |
|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.1 |
CPE | cpe:2.3:a:mit:kerberos_5:*:*:*:*:*:*:*:* | |
References | () https://web.mit.edu/kerberos/www/advisories/ - Vendor Advisory | |
References | () https://github.com/krb5/krb5/commit/55fbf435edbe2e92dd8101669b1ce7144bc96fef - Patch |
28 Jun 2024, 23:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-06-28 23:15
Updated : 2025-03-13 21:15
NVD link : CVE-2024-37371
Mitre link : CVE-2024-37371
JSON object : View
Products Affected
debian
- debian_linux
mit
- kerberos_5
CWE