Related Vulnerabilities: CVE-2021-37750  

The Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) before 1.19.3 has a NULL pointer dereference in kdc/do_tgs_req.c via a FAST inner body that lacks a server field.

Severity Medium

Remote Yes

Type Denial of service

Description

The Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) before 1.19.3 has a NULL pointer dereference in kdc/do_tgs_req.c via a FAST inner body that lacks a server field.

AVG-2312 krb5 1.19.2-1 Medium Vulnerable

https://krbdev.mit.edu/rt/Ticket/Display.html?id=9008
https://github.com/krb5/krb5/commit/d775c95af7606a51bf79547a94fa52ddd1cb7f49