CVE-2024-37371 log

Source
Severity Medium
Remote Yes
Type Denial of service
Description
In MIT Kerberos 5 (aka krb5) before 1.21.3, an attacker can cause invalid memory reads during GSS message token handling by sending message tokens with invalid length fields.
Group Package Affected Fixed Severity Status Ticket
AVG-2856 krb5 1.21.2-1 1.21.3-1 Medium Fixed
References
https://github.com/krb5/krb5/commit/55fbf435edbe2e92dd8101669b1ce7144bc96fef