The Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) before 1.18.5 and 1.19.x before 1.19.3 has a NULL pointer dereference in kdc/dotgsreq.c via a FAST inner body that lacks a server field.
{
"unresolved_ranges": [
{
"source": "CPE_FIELD",
"cpes": [
"cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*"
],
"extracted_events": [
{
"last_affected": "9.0"
}
],
"vendor_product": "debian:debian_linux"
},
{
"source": "CPE_FIELD",
"cpes": [
"cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:*"
],
"extracted_events": [
{
"last_affected": "33"
}
],
"vendor_product": "fedoraproject:fedora"
},
{
"source": "CPE_FIELD",
"cpes": [
"cpe:2.3:a:mit:kerberos_5:*:*:*:*:*:*:*:*"
],
"extracted_events": [
{
"fixed": "1.18.5"
}
],
"vendor_product": "mit:kerberos_5"
},
{
"source": "CPE_FIELD",
"cpes": [
"cpe:2.3:a:oracle:communications_cloud_native_core_network_slice_selection_function:22.1.0:*:*:*:*:*:*:*"
],
"extracted_events": [
{
"last_affected": "22.1.0"
}
],
"vendor_product": "oracle:communications_cloud_native_core_network_slice_selection_function"
},
{
"source": "CPE_FIELD",
"cpes": [
"cpe:2.3:a:starwindsoftware:starwind_virtual_san:v8r13:14338:*:*:*:*:*:*"
],
"extracted_events": [
{
"last_affected": "v8r13-14338"
}
],
"vendor_product": "starwindsoftware:starwind_virtual_san"
}
]
}{
"cpe": "cpe:2.3:a:mit:kerberos_5:*:*:*:*:*:*:*:*",
"source": "CPE_FIELD",
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "1.18.5"
},
{
"introduced": "1.19.0"
},
{
"fixed": "1.19.3"
}
]
}