CVE-2020-28196
HIGHMIT Kerberos <1.17.2, <1.18.x-1.18.3 - RCE
Title source: llmDescription
MIT Kerberos 5 (aka krb5) before 1.17.2 and 1.18.x before 1.18.3 allows unbounded recursion via an ASN.1-encoded Kerberos message because the lib/krb5/asn.1/asn1_encode.c support for BER indefinite lengths lacks a recursion limit.
Scores
CVSS v3
7.5
EPSS
0.0050
EPSS Percentile
65.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Classification
CWE
CWE-674
Status
published
Affected Products (12)
mit/kerberos_5
< 1.17.2
fedoraproject/fedora
netapp/active_iq_unified_manager
netapp/active_iq_unified_manager
netapp/cloud_backup
netapp/oncommand_insight
netapp/oncommand_workflow_automation
netapp/snapcenter
oracle/communications_cloud_native_core_policy
oracle/communications_offline_mediation_controller
oracle/communications_pricing_design_center
oracle/mysql_server
< 8.0.23
Timeline
Published
Nov 06, 2020
Tracked Since
Feb 18, 2026