First published: Tue Jan 16 2018(Updated: )
An issue was discovered in MIT Kerberos 5 (aka krb5) through 1.16. The pre-defined function "strlen" is getting a "NULL" string as a parameter value in plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c in the Key Distribution Center (KDC), which allows remote authenticated users to cause a denial of service (NULL pointer dereference) via a modified kadmin client.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
MIT Kerberos | <=5-1.16 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-5710 is an issue in MIT Kerberos 5 (krb5) through version 1.16 that allows remote authenticated users to cause a denial of service.
CVE-2018-5710 affects MIT Kerberos 5 by allowing remote authenticated users to cause a denial of service.
The severity of CVE-2018-5710 is medium with a severity value of 6.5.
To fix CVE-2018-5710, it is recommended to update MIT Kerberos 5 to a version higher than 1.16.
The CWE of CVE-2018-5710 is CWE-476.