CVE-2020-28196
06.11.2020, 08:15
MIT Kerberos 5 (aka krb5) before 1.17.2 and 1.18.x before 1.18.3 allows unbounded recursion via an ASN.1-encoded Kerberos message because the lib/krb5/asn.1/asn1_encode.c support for BER indefinite lengths lacks a recursion limit.Enginsight
| Vendor | Product | Version |
|---|---|---|
| mit | kerberos_5 | 𝑥 < 1.17.2 |
| mit | kerberos_5 | 1.18.0 ≤ 𝑥 < 1.18.3 |
| netapp | active_iq_unified_manager | - |
| netapp | active_iq_unified_manager | - |
| netapp | cloud_backup | - |
| netapp | oncommand_insight | - |
| netapp | oncommand_workflow_automation | - |
| netapp | snapcenter | - |
| oracle | communications_cloud_native_core_policy | 1.14.0 |
| oracle | communications_offline_mediation_controller | 12.0.0.3.0 |
| oracle | communications_pricing_design_center | 12.0.0.3.0 |
| oracle | mysql_server | 𝑥 ≤ 8.0.23 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Common Weakness Enumeration
References