Vulnerability Description
The Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) before 1.18.5 and 1.19.x before 1.19.3 has a NULL pointer dereference in kdc/do_tgs_req.c via a FAST inner body that lacks a server field.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mit | Kerberos 5 | < 1.18.5 |
| Fedoraproject | Fedora | 33 |
| Debian | Debian Linux | 9.0 |
| Starwindsoftware | Starwind Virtual San | v8r13 |
| Oracle | Communications Cloud Native Core Network Slice Selection Function | 22.1.0 |
Related Weaknesses (CWE)
References
- https://github.com/krb5/krb5/commit/d775c95af7606a51bf79547a94fa52ddd1cb7f49PatchThird Party Advisory
- https://github.com/krb5/krb5/releasesRelease NotesThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2021/09/msg00019.htmlMailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://security.netapp.com/advisory/ntap-20210923-0002/Third Party Advisory
- https://web.mit.edu/kerberos/advisories/Vendor Advisory
- https://www.oracle.com/security-alerts/cpujul2022.htmlPatchThird Party Advisory
- https://www.starwindsoftware.com/security/sw-20220817-0004/Third Party Advisory
- https://github.com/krb5/krb5/commit/d775c95af7606a51bf79547a94fa52ddd1cb7f49PatchThird Party Advisory
- https://github.com/krb5/krb5/releasesRelease NotesThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2021/09/msg00019.htmlMailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://security.netapp.com/advisory/ntap-20210923-0002/Third Party Advisory
- https://web.mit.edu/kerberos/advisories/Vendor Advisory
- https://www.oracle.com/security-alerts/cpujul2022.htmlPatchThird Party Advisory
FAQ
What is CVE-2021-37750?
CVE-2021-37750 is a vulnerability with a CVSS score of 6.5 (MEDIUM). The Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) before 1.18.5 and 1.19.x before 1.19.3 has a NULL pointer dereference in kdc/do_tgs_req.c via a FAST inner body that lacks a server field...
How severe is CVE-2021-37750?
CVE-2021-37750 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-37750?
Check the references section above for vendor advisories and patch information. Affected products include: Mit Kerberos 5, Fedoraproject Fedora, Debian Debian Linux, Starwindsoftware Starwind Virtual San, Oracle Communications Cloud Native Core Network Slice Selection Function.