cbcvebase.
CVE-2020-28196
published 2020-11-06

CVE-2020-28196: MIT Kerberos 5 (aka krb5) before 1.17.2 and 1.18.x before 1.18.3 allows unbounded recursion via an ASN.1-encoded Kerberos message because the…

high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
MIT Kerberos 5 (aka krb5) before 1.17.2 and 1.18.x before 1.18.3 allows unbounded recursion via an ASN.1-encoded Kerberos message because the lib/krb5/asn.1/asn1_encode.c support for BER indefinite lengths lacks a recursion limit.

Affected

13 ranges
VendorProductVersion rangeFixed in
debiankrb5< krb5 1.18.3-1 (bookworm)krb5 1.18.3-1 (bookworm)
fedoraprojectfedora
mitkerberos_5< 1.17.21.17.2
mitkerberos_5>= 1.18.0 < 1.18.31.18.3
mitkrb5>= 0 < 1.18.3-11.18.3-1
mitkrb5>= 0 < 1.18.3-11.18.3-1
mitkrb5>= 0 < 1.18.3-11.18.3-1
mitkrb5>= 0 < 1.18.3-11.18.3-1
msrccm1_krb5_1.18.4-1_on_cbl_mariner_1.0
oraclecommunications_cloud_native_core_policy
oraclecommunications_offline_mediation_controller
oraclecommunications_pricing_design_center
oraclemysql_server<= 8.0.23

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH