CVE-2023-36054

Source
https://cve.org/CVERecord?id=CVE-2023-36054
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2023-36054.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2023-36054
Downstream
Related
Published
2023-08-07T00:00:00Z
Modified
2026-05-28T03:52:37.842279797Z
Summary
[none]
Details

lib/kadm5/kadmrpcxdr.c in MIT Kerberos 5 (aka krb5) before 1.20.2 and 1.21.x before 1.21.1 frees an uninitialized pointer. A remote authenticated user can trigger a kadmind crash. This occurs because xdrkadm5principalentrec does not validate the relationship between nkeydata and the keydata array count.

Database specific
{
    "cna_assigner": "mitre",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/36xxx/CVE-2023-36054.json"
}
References

Affected packages

Git / github.com/krb5/krb5

Affected ranges

Type
GIT
Repo
https://github.com/krb5/krb5
Events

Affected versions

krb5-1.*
krb5-1.21-final

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2023-36054.json"