PT-2018-2734 · Mit+4 · Mit-Krb5+4

Pooja Anil

+1

·

Published

2018-01-03

·

Updated

2025-05-05

·

CVE-2018-5729

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions MIT krb5 versions 1.6 or later
Description The issue is related to a null pointer dereference in the Kerberos authentication protocol, which can lead to a denial of service. An authenticated kadmin with permission to add principals to an LDAP Kerberos database can exploit this by supplying tagged data internal to the database module, causing a denial of service or bypassing a DN container check.
Recommendations For MIT krb5 versions 1.6 or later, consider restricting access to the kadmin functionality to prevent exploitation until a patch is available. As a temporary workaround, avoid using the database module with tagged data that is internal to it. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

NULL Pointer Dereference

Weakness Enumeration

Related Identifiers

ALT-PU-2018-2231
BDU:2019-01636
CESA-2018_3071
CVE-2018-5729
DLA-1643-1
DLA-2771-1
MGASA-2018-0155
OPENSUSE-SU-2019:0139-1
OPENSUSE-SU-2019_0139-1
OPENSUSE-SU-2024:10899-1
RHSA-2018:3071
RHSA-2018_3071
SUSE-SU-2018:0846-1
SUSE-SU-2018:0859-1
SUSE-SU-2018_0846-1
SUSE-SU-2019:0175-1
SUSE-SU-2019_0175-1

Affected Products

Alt Linux
Centos
Mit-Krb5
Red Hat
Suse