You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Name: mit-krb5 CVEs: CVE-2023-36054 CVSSs: 6.5 Action Needed: update to >= 1.20.2 or >= 1.21.1
Summary: lib/kadm5/kadm_rpc_xdr.c in MIT Kerberos 5 (aka krb5) before 1.20.2 and 1.21.x before 1.21.1 frees an uninitialized pointer. A remote authenticated user can trigger a kadmind crash. This occurs because _xdr_kadm5_principal_ent_rec does not validate the relationship between n_key_data and the key_data array count.
Name: mit-krb5
CVEs: CVE-2023-36054
CVSSs: 6.5
Action Needed: update to >= 1.20.2 or >= 1.21.1
Summary: lib/kadm5/kadm_rpc_xdr.c in MIT Kerberos 5 (aka krb5) before 1.20.2 and 1.21.x before 1.21.1 frees an uninitialized pointer. A remote authenticated user can trigger a kadmind crash. This occurs because _xdr_kadm5_principal_ent_rec does not validate the relationship between n_key_data and the key_data array count.
See also https://bugzilla.redhat.com/show_bug.cgi?id=2230178.
refmap.gentoo: TBD
The text was updated successfully, but these errors were encountered: