CVE-2022-42898: Buffer Overflow
PAC parsing in MIT Kerberos 5 (aka krb5) before 1.19.4 and 1.20.x before 1.20.1 has integer overflows that may lead to remote code execution (in KDC, kadmind, or a GSS or Kerberos application server) on 32-bit platforms (which have a resultant heap-based buffer overflow), and cause a denial of service on other platforms. This occurs in krb5pacparse in lib/krb5/krb/pac.c. Heimdal before 7.7.1 has "a similar bug."
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID of this security issue?
The vulnerability ID of this security issue is CVE-2022-42898.
What is the severity rating of CVE-2022-42898?
CVE-2022-42898 has a severity rating of 8.8 (High).
Which software versions are affected by CVE-2022-42898?
MIT Kerberos 5 versions before 1.19.4 and 1.20.x before 1.20.1 are affected.
How can CVE-2022-42898 lead to remote code execution?
CVE-2022-42898 can lead to remote code execution due to integer overflows in PAC parsing.
Where can I find more information about CVE-2022-42898?
You can find more information about CVE-2022-42898 in the references provided: [link1] [link2] [link3].