Description
MIT Kerberos 5 (aka krb5) before 1.17.2 and 1.18.x before 1.18.3 allows unbounded recursion via an ASN.1-encoded Kerberos message because the lib/krb5/asn.1/asn1_encode.c support for BER indefinite lengths lacks a recursion limit.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-2437-1 | krb5 security update |
Debian DSA |
DSA-4795-1 | krb5 security update |
EUVD |
EUVD-2020-20680 | MIT Kerberos 5 (aka krb5) before 1.17.2 and 1.18.x before 1.18.3 allows unbounded recursion via an ASN.1-encoded Kerberos message because the lib/krb5/asn.1/asn1_encode.c support for BER indefinite lengths lacks a recursion limit. |
Ubuntu USN |
USN-4635-1 | Kerberos vulnerability |
References
History
Wed, 03 Dec 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Subscriptions
Fedoraproject
Subscribe
Fedora
Subscribe
Mit
Subscribe
Kerberos 5
Subscribe
Netapp
Subscribe
Active Iq Unified Manager
Subscribe
Cloud Backup
Subscribe
Oncommand Insight
Subscribe
Oncommand Workflow Automation
Subscribe
Snapcenter
Subscribe
Oracle
Subscribe
Communications Cloud Native Core Policy
Subscribe
Communications Offline Mediation Controller
Subscribe
Communications Pricing Design Center
Subscribe
Mysql Server
Subscribe
Redhat
Subscribe
Enterprise Linux
Subscribe
Rhev Hypervisor
Subscribe
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-12-03T18:15:34.180Z
Reserved: 2020-11-03T00:00:00.000Z
Link: CVE-2020-28196
Updated: 2024-08-04T16:33:58.154Z
Status : Modified
Published: 2020-11-06T08:15:13.860
Modified: 2025-12-03T19:15:52.130
Link: CVE-2020-28196
OpenCVE Enrichment
No data.
Weaknesses
Debian DLA
Debian DSA
EUVD
Ubuntu USN