A vulnerability was found in MIT Kerberos 5 up to 1.18.4/1.19.2 (Network Authentication Software) and classified as problematic. This issue affects an unknown code of the file kdc/do_tgs_req.c of the component Key Distribution Center Handler. Upgrading to version 1.18.5 or 1.19.3 eliminates this vulnerability. Applying a patch is able to eliminate this problem. The bugfix is ready for download at github.com. The best possible mitigation is suggested to be upgrading to the latest version.
MIT Kerberos 5 up to 1.18.4/1.19.2 Key Distribution Center kdc/do_tgs_req.c null pointer dereference
- Virtual Patching
- August 23, 2021
- 12:04 pm
CVE-2024-31869 : APACHE AIRFLOW UP TO 2.8.4 CONFIGURATION UI PAGE INFORMATION DISCLOSURE
Description Airflow versions 2.7.0 through 2.8.4 have a vulnerability that allows an authenticated user to see sensitive provider configuration via
CVE-2024-24856 : LINUX KERNEL UP TO 6.8 ACPI_ALLOCATE_ZEROED NULL POINTER DEREFERENCE
Description The memory allocation function ACPI_ALLOCATE_ZEROED does not guarantee a successful allocation, but the subsequent code directly dereferences the pointer
CVE-2024-2912 : BENTOML FRAMEWORK UP TO 1.2.4 POST REQUEST INSECURE DEFAULT INITIALIZATION OF RESOURCE
Description An insecure deserialization vulnerability exists in the BentoML framework, allowing remote code execution (RCE) by sending a specially crafted