MIT Kerberos 5 (aka krb5) before 1.17.2 and 1.18.x before 1.18.3 allows unbounded recursion via an ASN.1-encoded Kerberos message because the lib/krb5/asn.1/asn1_encode.c support for BER indefinite lengths lacks a recursion limit.
2020-11-06T08:15:13.860
2024-11-21T05:22:27.613
Modified
CVSSv3.1: 7.5 (HIGH)
AV:N/AC:L/Au:N/C:N/I:N/A:P
10.0
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | mit | kerberos_5 | < 1.17.2 | Yes |
Application | mit | kerberos_5 | < 1.18.3 | Yes |
Operating System | fedoraproject | fedora | 31 | Yes |
Application | netapp | active_iq_unified_manager | - | Yes |
Application | netapp | active_iq_unified_manager | - | Yes |
Application | netapp | cloud_backup | - | Yes |
Application | netapp | oncommand_insight | - | Yes |
Application | netapp | oncommand_workflow_automation | - | Yes |
Application | netapp | snapcenter | - | Yes |
Application | oracle | communications_cloud_native_core_policy | 1.14.0 | Yes |
Application | oracle | communications_offline_mediation_controller | 12.0.0.3.0 | Yes |
Application | oracle | communications_pricing_design_center | 12.0.0.3.0 | Yes |
Application | oracle | mysql_server | ≤ 8.0.23 | Yes |