CVE-2018-5729: Null Pointer Dereference
A flaw was found in MIT krb5 1.6 or later, an authenticated kadmin user with permission to add principals to an LDAP Kerberos database can cause a null dereference in kadmind, or circumvent a DN container check, by supplying tagged data intended to be internal to the database module.
Reference: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=891869
Upstream patch: https://github.com/krb5/krb5/commit/e1caf6fb74981da62039846931ebdffed71309d1
Other sources
MIT krb5 1.6 or later allows an authenticated kadmin with permission to add principals to an LDAP Kerberos database to cause a denial of service (NULL pointer dereference) or bypass a DN container check by supplying tagged data that is internal to the database module.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/krb5to a version that resolves this vulnerability.Fixed in 1.18.3-6+deb11u5Fixed in 1.18.3-6+deb11u7Fixed in 1.20.1-2+deb12u4Fixed in 1.20.1-2+deb12u2Fixed in 1.21.3-5Fixed in 1.22.1-2 - Upgrade
Upgrade
MIT krb5to a version that resolves this vulnerability.Fixed in 1.6 or laterPatch e1caf6fb74981da62039846931ebdffed71309d1
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2018-5729.
What is the severity level of CVE-2018-5729?
CVE-2018-5729 has a severity level of 4.7 (high).
Which software versions are affected by CVE-2018-5729?
MIT krb5 1.6 or later versions are affected by CVE-2018-5729.
How can an attacker exploit CVE-2018-5729?
An authenticated kadmin with permission to add principals to an LDAP Kerberos database can cause a denial of service (NULL pointer dereference) or bypass a DN container check by supplying tagged data that is internal to the database module.
Are there any official references for CVE-2018-5729?
Yes, you can find official references for CVE-2018-5729 at the following links: http://www.securitytracker.com/id/1042071, https://access.redhat.com/errata/RHBA-2019:0327, https://access.redhat.com/errata/RHSA-2018:3071.