CVE-2021-37750 - log back

CVE-2021-37750 edited at 23 Aug 2021 11:06:49
Severity
- Unknown
+ Medium
Remote
- Unknown
+ Remote
Type
- Unknown
+ Denial of service
Description
+ The Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) before 1.19.3 has a NULL pointer dereference in kdc/do_tgs_req.c via a FAST inner body that lacks a server field.
References
+ https://krbdev.mit.edu/rt/Ticket/Display.html?id=9008
+ https://github.com/krb5/krb5/commit/d775c95af7606a51bf79547a94fa52ddd1cb7f49
Notes
CVE-2021-37750 created at 23 Aug 2021 11:04:15