NULL Pointer Dereference
Affecting krb5 package, versions <1.13.2+dfsg-5ubuntu2.1
Report new vulnerabilities
Do your applications use this vulnerable package?
Test your applications
Overview
MIT krb5 1.6 or later allows an authenticated kadmin with permission to add principals to an LDAP Kerberos database to cause a denial of service (NULL pointer dereference) or bypass a DN container check by supplying tagged data that is internal to the database module.
References
CVSS Score
4.7
low severity
-
Attack VectorNetwork
-
Attack ComplexityLow
-
Privileges RequiredHigh
-
User InteractionNone
-
ScopeUnchanged
-
ConfidentialityLow
-
IntegrityLow
-
AvailabilityLow
- CVE
- CVE-2018-5729
- CWE
- CWE-476
- Snyk ID
- SNYK-UBUNTU1604-KRB5-396221
- Disclosed
- 06 Mar, 2018
- Published
- 06 Mar, 2018