CVE-2024-37371

Name
CVE-2024-37371
Description
In MIT Kerberos 5 (aka krb5) before 1.21.3, an attacker can cause invalid memory reads during GSS message token handling by sending message tokens with invalid length fields.
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
cve@mitre.org https://github.com/krb5/krb5/commit/55fbf435edbe2e92dd8101669b1ce7144bc96fef
cve@mitre.org https://web.mit.edu/kerberos/www/advisories/
af854a3a-2127-422b-91ae-364da2661108 https://security.netapp.com/advisory/ntap-20241108-0009/

Match rules

CPE URI Source package Min version Max version
n/a == n/a == n/a
cpe:2.3:a:mit:kerberos_5:*:*:*:*:*:*:*:* kerberos_5 >= None < 1.21.3

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
krb5 3.18-main 1.20.2-r1 Natanael Copa <ncopa@alpinelinux.org> fixed
krb5 3.17-main 1.20.2-r1 Natanael Copa <ncopa@alpinelinux.org> fixed