The Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) before 1.18.5 and 1.19.x before 1.19.3 has a NULL pointer dereference in kdc/dotgsreq.c via a FAST inner body that lacks a server field.
{
"versions": [
{
"introduced": "0"
},
{
"fixed": "1.18.5"
},
{
"introduced": "1.19.0"
},
{
"fixed": "1.19.3"
}
]
}"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2021-37750.json"
[
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "33"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "9.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "v8r13-14338"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "22.1.0"
}
]
}
]