Security restrictions bypass in Kerberos 5 - CVE-2018-5730
Published: March 14, 2018 / Updated: March 14, 2018
Vulnerability identifier: #VU11076
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-5730
CWE-ID: CWE-264
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote authenticated attacker to bypass security restrictions on a targeted system.
The weakness exists due to insufficient security restrictions. A remote attacker can add crafted principals to the Lightweight Directory Access Protocol (LDAP) database and bypass a DN containership check.
The weakness exists due to insufficient security restrictions. A remote attacker can add crafted principals to the Lightweight Directory Access Protocol (LDAP) database and bypass a DN containership check.
Affected software
Kerberos 5
Arch Linux
Amazon Linux AMI
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for Power
Opensuse
Fedora
IBM Security Verify Access
krb5
Arch Linux
Amazon Linux AMI
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for Power
Opensuse
Fedora
IBM Security Verify Access
krb5
How to mitigate CVE-2018-5730
Install update from vendor's website.
IBM Security Verify Access - update to 10.0.4.0
krb5 - addressed in versions 1.15.2-7.fc26, 1.15.2-7.fc27
krb5 - addressed in versions 1.15.2-7.fc26, 1.15.2-7.fc27