Alpaquita LinuxStreamSecurity Advisory
Search Cve

CVE-2024-37371

Published: June 28, 2024Last modified: July 9, 2024

Description

In MIT Kerberos 5 (aka krb5) before 1.21.3, an attacker can cause invalid memory reads during GSS message token handling by sending message tokens with invalid length fields.

Severity score breakdown

ParameterValue
Base score9.1
Attack VectorNETWORK
Attack complexityLOW
Privileges requiredNONE
User interactionNONE
ScopeUNCHANGED
ConfidentialityHIGH
Integrity impactNONE
Availability impactHIGH
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H

Status

ProductReleasePackageStatus
Alpaquita Linux23 LTSkrb5Fixed (1.20.2-r2)
Streamkrb5Fixed (1.21.3-r0)

References

Published BELL-SAs

ON THIS PAGE