Files
Soumya Sambu 86124cc625 krb5: Fix CVE-2023-36054
lib/kadm5/kadm_rpc_xdr.c in MIT Kerberos 5 (aka krb5) before 1.20.2
and 1.21.x before 1.21.1 frees an uninitialized pointer. A remote
authenticated user can trigger a kadmind crash. This occurs because
_xdr_kadm5_principal_ent_rec does not validate the relationship
between n_key_data and the key_data array count.

References:
https://nvd.nist.gov/vuln/detail/CVE-2023-36054

Signed-off-by: Soumya Sambu <soumya.sambu@windriver.com>
Signed-off-by: Armin Kuster <akuster808@gmail.com>
2023-09-04 11:55:22 -04:00
..
2023-01-21 10:02:02 -08:00
2022-01-25 10:56:04 -08:00
2022-07-19 18:38:44 -07:00
2023-02-07 20:56:08 -08:00
2023-09-04 11:55:22 -04:00
2023-03-10 17:21:15 -08:00
2023-03-10 17:21:15 -08:00
2022-03-03 23:07:50 -08:00
2022-11-23 08:25:30 -08:00
2023-07-16 15:15:37 -04:00
2022-12-27 16:03:06 -08:00
2022-08-27 07:37:45 -07:00
2023-02-22 01:03:38 -08:00
2023-02-01 09:11:49 -08:00