{"id":"ECHO-f800-2733-e5c3","summary":"Disputed by upstream.\n1. non-issue according to debian.\n2. This is essentially an integer truncation issue, and not an integer \noverflow. We have determined that this should not affect any other data\nallocated close to the 16-bit integer in question\n\"dbentry-\u003e n_key_data\". Red Hat Product Security does not consider this\nissue as a security flaw.\n","modified":"2026-09-15T03:42:37.830899634Z","published":"2025-09-15T01:09:15.020554Z","withdrawn":"2025-08-03T16:59:06.549Z","upstream":["CVE-2018-5709","GHSA-9g2q-jwhw-j832"],"references":[{"type":"WEB","url":"https://advisory.echohq.com/cve/CVE-2018-5709"}],"affected":[{"package":{"name":"krb5","ecosystem":"Echo","purl":"pkg:deb/echo/krb5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.20.1-2+deb12u2"}]}],"database_specific":{"source":"https://advisory.echohq.com/osv/ECHO-f800-2733-e5c3.json"}}],"schema_version":"1.9.0"}