ECHO-f800-2733-e5c3

See a problem?
Import Source
https://advisory.echohq.com/osv/ECHO-f800-2733-e5c3.json
JSON Data
https://api.osv.dev/v1/vulns/ECHO-f800-2733-e5c3
Upstream
  • GHSA-9g2q-jwhw-j832
Withdrawn
2025-08-03T16:59:06Z
Published
2025-09-15T01:09:15Z
Modified
2026-09-15T03:42:37Z
Summary
Disputed by upstream. 1. non-issue according to debian. 2. This is essentially an integer truncation issue, and not an integer overflow. We have determined that this should not affect any other data allocated close to the 16-bit integer in question "dbentry-> n_key_data". Red Hat Product Security does not consider this issue as a security flaw.
Details
References

Affected packages

Echo / krb5

Package

Name
krb5
Purl
pkg:deb/echo/krb5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.20.1-2+deb12u2

Database specific

source
"https://advisory.echohq.com/osv/ECHO-f800-2733-e5c3.json"