VDB

MAGEIA-2022-467

MAGEIA-2022-467 PUBLISHED

Greg Hudson discovered integer overflow flaws in the PAC parsing in krb5, the MIT implementation of Kerberos, which may result in remote code execution (in a KDC, kadmin, or GSS or Kerberos application server process), information exposure (to a cross-realm KDC acting maliciously), or denial of service (KDC or kadmind process crash).

Affected Products

VendorProductVersions
Mageiakrb51.18.3-1.3.mga8, 0

Timeline

  • Dec 17, 2022 CVE Updated
  • Dec 17, 2022 CVE Published
  • Mar 17, 2026 Distribution Patch
  • Mar 17, 2026 Security Advisory
Open in Interactive Console →
$ Console Community · 100/wk Open console ›