Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-36054


lib/kadm5/kadm_rpc_xdr.c in MIT Kerberos 5 (aka krb5) before 1.20.2 and 1.21.x before 1.21.1 frees an uninitialized pointer. A remote authenticated user can trigger a kadmind crash. This occurs because _xdr_kadm5_principal_ent_rec does not validate the relationship between n_key_data and the key_data array count.


Published

2023-08-07T19:15:09.840

Last Modified

2024-11-21T08:09:15.227

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 6.5 (MEDIUM)

Weaknesses
  • Type: Primary
    CWE-824

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application mit kerberos_5 < 1.20.2 Yes
Application mit kerberos_5 1.21 Yes
Application mit kerberos_5 1.21 Yes
Operating System debian debian_linux 10.0 Yes
Application netapp active_iq_unified_manager - Yes
Application netapp clustered_data_ontap 9.0 Yes
Application netapp hci - Yes
Application netapp management_services_for_element_software - Yes
Application netapp ontap_tools - Yes

References