MIT Kerberos 5
Moderate fix1 remedy
cpe:2.3:a:mit:kerberos:*:*:*:*:*:*:*
Moderate fix1 remedy
- >= 1.18, < 1.22.3
An integer underflow vulnerability has been identified in MIT Kerberos 5 versions prior to 1.22.3. This vulnerability occurs when an application calls gss_accept_sec_context() on a system with a NegoEx mechanism registered. An unauthenticated remote attacker can exploit this vulnerability, leading to an out-of-bounds read of up to 52 bytes, which may cause the process to terminate.
Exploitation of this vulnerability causes a read overrun of up to 52 bytes, possibly leading to a process termination.
Users can apply the upstream patch available in commit 2e75f0d or update to a version containing the fix.