NULL pointer dereference in Kerberos 5 - CVE-2018-5729
Published: March 14, 2018 / Updated: March 14, 2018
Vulnerability identifier: #VU11080
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-5729
CWE-ID: CWE-476
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local attacker to cause DoS condition on the target system.
The weakness exists due to NULL pointer dereference. A local attacker can add crafted principals to the Lightweight Directory Access Protocol (LDAP) database and cause the service to crash.
The weakness exists due to NULL pointer dereference. A local attacker can add crafted principals to the Lightweight Directory Access Protocol (LDAP) database and cause the service to crash.
Affected software
Kerberos 5
Arch Linux
Amazon Linux AMI
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for Power
Opensuse
Fedora
krb5
Arch Linux
Amazon Linux AMI
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for Power
Opensuse
Fedora
krb5
How to mitigate CVE-2018-5729
Install update from vendor's website.
krb5 - addressed in versions 1.15.2-7.fc26, 1.15.2-7.fc27