{"id":"CVE-2024-37370","details":"In MIT Kerberos 5 (aka krb5) before 1.21.3, an attacker can modify the plaintext Extra Count field of a confidential GSS krb5 wrap token, causing the unwrapped token to appear truncated to the application.","modified":"2026-05-18T11:54:05.629812004Z","published":"2024-06-28T00:00:00Z","related":["ALSA-2024:5312","ALSA-2024:6166","SUSE-SU-2024:2300-1","SUSE-SU-2024:2302-1","SUSE-SU-2024:2303-1","SUSE-SU-2024:2305-1","SUSE-SU-2024:2307-1","SUSE-SU-2024:2322-1","SUSE-SU-2025:20051-1","openSUSE-SU-2024:14111-1"],"database_specific":{"cna_assigner":"mitre","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/37xxx/CVE-2024-37370.json"},"references":[{"type":"WEB","url":"https://cert-portal.siemens.com/productcert/html/ssa-082556.html"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/37xxx/CVE-2024-37370.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-37370"},{"type":"ADVISORY","url":"https://security.netapp.com/advisory/ntap-20241108-0007/"},{"type":"ADVISORY","url":"https://web.mit.edu/kerberos/www/advisories/"},{"type":"FIX","url":"https://github.com/krb5/krb5/commit/55fbf435edbe2e92dd8101669b1ce7144bc96fef"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/krb5/krb5","events":[{"introduced":"0"},{"fixed":"8f56f544dd179056e9b8d02552e6c5e392eb2966"}]}],"versions":["kfw-4.3-beta1","kfw-4.3-beta1-mit","krb5-1.21.2-final","krb5-1.21.1-final","krb5-1.21-final","krb5-1.21-beta1"],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-37370.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"}]}