Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:23829
HistoryApr 10, 2020 - 12:37 a.m.

Denial Of Service (DoS)

2020-04-1000:37:20
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
15

EPSS

0.031

Percentile

91.2%

krb5 is vulnerable to denial of service. Multiple input validation flaws were found in the MIT Kerberos GSS-API library’s implementation of the SPNEGO mechanism. A remote attacker could use these flaws to crash any network service utilizing the MIT Kerberos GSS-API library to authenticate users or, possibly, leak portions of the service’s memory.

References