In MIT Kerberos 5 (aka krb5) before 1.21.3, an attacker can cause invalid memory reads during GSS message token handling by sending message tokens with invalid length fields.
References
Configurations
History
13 Mar 2025, 21:15
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-125 |
Information
Published : 2024-06-28 23:15
Updated : 2025-03-13 21:15
NVD link : CVE-2024-37371
Mitre link : CVE-2024-37371
CVE.ORG link : CVE-2024-37371
JSON object : View
Products Affected
mit
- kerberos_5
debian
- debian_linux
CWE