Medium
Canonical Ubuntu
Demi Obenour discovered that Kerberos incorrectly handled certain ASN.1. An attacker could possibly use this issue to cause a denial of service.
CVEs contained in this USN include: CVE-2020-28196.
Severity is medium unless otherwise noted.
Users of affected products are strongly encouraged to follow the mitigations below. The Cloud Foundry project recommends upgrading the following releases:
2021-01-13: Initial vulnerability report published.
CPE | Name | Operator | Version |
---|---|---|---|
cflinuxfs3 | lt | 0.211.0 | |
xenial stemcells | lt | 315.202 | |
xenial stemcells | lt | 456.129 | |
xenial stemcells | lt | 621.93 | |
cf deployment | lt | 15.4.0 |