#VU93518 Input validation error in Kerberos 5 - CVE-2024-37370
Published: July 1, 2024
Kerberos 5
MIT
Description
The vulnerability allows a remote attacker to bypass implemented security restrictions.
The vulnerability exists due to insufficient validation of user-supplied input. A remote attacker can modify the plaintext Extra Count field of a confidential GSS krb5 wrap token, causing the unwrapped token to appear truncated to the application.