CVE-2018-5729

Name
CVE-2018-5729
Description
MIT krb5 1.6 or later allows an authenticated kadmin with permission to add principals to an LDAP Kerberos database to cause a denial of service (NULL pointer dereference) or bypass a DN container check by supplying tagged data that is internal to the database module.
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
Third Party Advisory https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/OIFUL3CPM4S5TOXTTOCQ3CUZN6XCXUTR/
Third Party Advisory https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/GK5T6JPMBHBPKS7HNGHYUUF4KKRMNSNU/
Patch https://github.com/krb5/krb5/commit/e1caf6fb74981da62039846931ebdffed71309d1
Issue Tracking https://bugzilla.redhat.com/show_bug.cgi?id=1551083
Third Party Advisory https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=891869
Third Party Advisory https://access.redhat.com/errata/RHSA-2018:3071
VDB Entry http://www.securitytracker.com/id/1042071
Mailing List https://lists.debian.org/debian-lts-announce/2019/01/msg00020.html
Third Party Advisory https://access.redhat.com/errata/RHBA-2019:0327
Mailing List https://lists.debian.org/debian-lts-announce/2021/09/msg00019.html
Mailing List https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GK5T6JPMBHBPKS7HNGHYUUF4KKRMNSNU/
Mailing List https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OIFUL3CPM4S5TOXTTOCQ3CUZN6XCXUTR/

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:mit:kerberos_5:*:*:*:*:*:*:*:* kerberos_5 >= 5-1.6 <= None
cpe:2.3:a:mit:kerberos_5:*:*:*:*:*:*:*:* kerberos_5 >= 5-1.6 < 5-1.21.2

Vulnerable and fixed packages

Source package Branch Version Maintainer Status