PT-2018-17115 · Mit+4 · Mit-Krb5+4
Laura Pardo
·
Published
2018-01-06
·
Updated
2025-05-05
·
CVE-2018-5730
CVSS v2.0
5.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions:
MIT krb5 versions 1.6 or later
Description:
The issue allows an authenticated kadmin with permission to add principals to an LDAP Kerberos database to circumvent a DN containership check. This can be done by supplying both a
linkdn and containerdn database argument, or by supplying a DN string which is a left extension of a container DN string but is not hierarchically within the container DN.Recommendations:
For MIT krb5 versions 1.6 or later, consider restricting the ability to add principals to the LDAP Kerberos database to prevent exploitation of this issue. As a temporary workaround, limit the use of
linkdn and containerdn database arguments to minimize the risk of circumventing the DN containership check. At the moment, there is no information about a newer version that contains a fix for this vulnerability. Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Centos
Mit-Krb5
Red Hat
Suse