ZeroHour

CVE-2024-37371

CVSS 3.1
9.1 critical
EPSS
2%p78
Published
()
Modified
Description

In MIT Kerberos 5 (aka krb5) before 1.21.3, an attacker can cause invalid memory reads during GSS message token handling by sending message tokens with invalid length fields.

Vendors
mitdebian
Products
kerberos 5, debian linux
Weakness
CWE-125
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H

In the news