In MIT Kerberos 5 (aka krb5) before 1.21.3, an attacker can cause invalid memory reads during GSS message token handling by sending message tokens with invalid length fields.
References
Configurations
History
No history.
Information
Published : 2024-06-28 23:15
Updated : 2025-11-03 21:16
NVD link : CVE-2024-37371
Mitre link : CVE-2024-37371
CVE.ORG link : CVE-2024-37371
JSON object : View
Products Affected
debian
- debian_linux
mit
- kerberos_5
CWE
