CVE-2019-14844

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
26/09/2019
Last modified:
12/02/2023

Description

A flaw was found in, Fedora versions of krb5 from 1.16.1 to, including 1.17.x, in the way a Kerberos client could crash the KDC by sending one of the RFC 4556 "enctypes". A remote unauthenticated user could use this flaw to crash the KDC.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:mit:kerberos_5:*:*:*:*:*:*:*:* 1.16.1 (including) 1.17.1 (including)
cpe:2.3:o:fedoraproject:fedora:29:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:30:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:31:*:*:*:*:*:*:*