https://seclists.org/oss-sec/2024/q2/312: Kerberos 1.21.3 fixes vulnerabilities in GSS message token handling
Published Jun 28, 2024
·Updated
Affected Software
1 affected component
MIT Kerberos
Frequently Asked Questions
1
What vulnerabilities are addressed in CVE-2024-37370 and CVE-2024-37371?
CVE-2024-37370 and CVE-2024-37371 address vulnerabilities in GSS message token handling in MIT Kerberos.
2
What is the severity of CVE-2024-37370 and CVE-2024-37371?
The severity rating for CVE-2024-37370 and CVE-2024-37371 has not been explicitly stated, but they are significant enough to warrant a patch in the latest release.
3
How do I fix CVE-2024-37370 and CVE-2024-37371?
To fix CVE-2024-37370 and CVE-2024-37371, you should upgrade to MIT Kerberos version 1.21.3 or later.
4
When was MIT Kerberos version 1.21.3 released?
MIT Kerberos version 1.21.3 was released on June 26, 2024.
5
Who announced the release of MIT Kerberos 1.21.3?
The release of MIT Kerberos 1.21.3 was announced by the Kerberos development team through their mailing list.