VDB
GCVE-110-MAGEIA-2024-253
GCVE-110-MAGEIA-2024-253
Advisory Published
Before 1.21.3, an attacker can modify the plaintext Extra Count field of
a confidential GSS krb5 wrap token, causing the unwrapped token to
appear truncated to the application. (CVE-2024-37370)
Before 1.21.3, an attacker can cause invalid memory reads during GSS
message token handling by sending message tokens with invalid length
fields. (CVE-2024-37371)
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| Mageia | krb5 | 0 (affected), 1.20.1-1.2.mga9 (unaffected) | — |
References
Browse GCVE Records
73,877 records in the GCVE database · Updated July 20, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.