ZeroHour

CVE-2020-28196

CVSS 3.1
7.5 high
EPSS
4%p91
Published
()
Modified
Description

MIT Kerberos 5 (aka krb5) before 1.17.2 and 1.18.x before 1.18.3 allows unbounded recursion via an ASN.1-encoded Kerberos message because the lib/krb5/asn.1/asn1_encode.c support for BER indefinite lengths lacks a recursion limit.

Vendors
mitfedoraprojectnetapporacle
Products
kerberos 5, fedora, active iq unified manager, cloud backup, oncommand insight, oncommand workflow automation, snapcenter, communications cloud native core policy, communications offline mediation controller, communications pricing design center, mysql server
Weakness
CWE-674
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.