CVE-2020-28196
06.11.2020, 08:15
MIT Kerberos 5 (aka krb5) before 1.17.2 and 1.18.x before 1.18.3 allows unbounded recursion via an ASN.1-encoded Kerberos message because the lib/krb5/asn.1/asn1_encode.c support for BER indefinite lengths lacks a recursion limit.Enginsight
Vendor | Product | Version |
---|---|---|
mit | kerberos_5 | 𝑥 < 1.17.2 |
mit | kerberos_5 | 1.18.0 ≤ 𝑥 < 1.18.3 |
netapp | active_iq_unified_manager | - |
netapp | active_iq_unified_manager | - |
netapp | cloud_backup | - |
netapp | oncommand_insight | - |
netapp | oncommand_workflow_automation | - |
netapp | snapcenter | - |
oracle | communications_cloud_native_core_policy | 1.14.0 |
oracle | communications_offline_mediation_controller | 12.0.0.3.0 |
oracle | communications_pricing_design_center | 12.0.0.3.0 |
oracle | mysql_server | 𝑥 ≤ 8.0.23 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Common Weakness Enumeration
References