CVE-2023-36054
07.08.2023, 19:15
lib/kadm5/kadm_rpc_xdr.c in MIT Kerberos 5 (aka krb5) before 1.20.2 and 1.21.x before 1.21.1 frees an uninitialized pointer. A remote authenticated user can trigger a kadmind crash. This occurs because _xdr_kadm5_principal_ent_rec does not validate the relationship between n_key_data and the key_data array count.Enginsight
Vendor | Product | Version |
---|---|---|
mit | kerberos_5 | 𝑥 < 1.20.2 |
mit | kerberos_5 | 1.21 |
mit | kerberos_5 | 1.21:beta1 |
debian | debian_linux | 10.0 |
netapp | active_iq_unified_manager | - |
netapp | clustered_data_ontap | 9.0 |
netapp | hci | - |
netapp | management_services_for_element_software | - |
netapp | ontap_tools | - |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Ubuntu Product | |||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
krb5 |
|
Common Weakness Enumeration
References