In MIT Kerberos 5 (aka krb5) before 1.21.3, an attacker can cause invalid memory reads during GSS message token handling by sending message tokens with invalid length fields.
References
Configurations
History
03 Nov 2025, 21:16
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
13 Mar 2025, 21:15
| Type | Values Removed | Values Added |
|---|---|---|
| CWE | CWE-125 |
Information
Published : 2024-06-28 23:15
Updated : 2025-11-03 21:16
NVD link : CVE-2024-37371
Mitre link : CVE-2024-37371
CVE.ORG link : CVE-2024-37371
JSON object : View
Products Affected
debian
- debian_linux
mit
- kerberos_5
CWE
