CVE-2018-5730
MIT krb5 1.6 or later allows an authenticated kadmin with permission to add principals to an LDAP Kerberos database to circumvent a DN containership check by supplying both a "linkdn" and "containerdn" database argument, or by supplying a DN string…
Does this matter?
Lower severity and a low EPSS score (2.24%). Track it; it rarely justifies an emergency change on its own.
Description
MIT krb5 1.6 or later allows an authenticated kadmin with permission to add principals to an LDAP Kerberos database to circumvent a DN containership check by supplying both a "linkdn" and "containerdn" database argument, or by supplying a DN string which is a left extension of a container DN string but is not hierarchically within the container DN.
- CVSS 3.1
- 3.8 LOWCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N
- EPSS
- 2.24% probability · 82th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-90
- Affected
- mit/kerberos 5 · fedoraproject/fedora · debian/debian linux · redhat/enterprise linux desktop · redhat/enterprise linux server · redhat/enterprise linux workstation
- Source
- cve@mitre.org
References
- http://www.securitytracker.com/id/1042071Broken Link, Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHBA-2019:0327Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:3071Third Party Advisory
- https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=891869Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1551082Issue Tracking, Patch, Third Party Advisory
- https://github.com/krb5/krb5/commit/e1caf6fb74981da62039846931ebdffed71309d1Patch, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2019/01/msg00020.htmlMailing List, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2021/09/msg00019.htmlMailing List, Third Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GK5T6JPMBHBPKS7HNGHYUUF4KKRMNSNU/Mailing List, Third Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OIFUL3CPM4S5TOXTTOCQ3CUZN6XCXUTR/Mailing List, Third Party Advisory
- http://www.securitytracker.com/id/1042071Broken Link, Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHBA-2019:0327Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:3071Third Party Advisory
- https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=891869Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1551082Issue Tracking, Patch, Third Party Advisory
- https://github.com/krb5/krb5/commit/e1caf6fb74981da62039846931ebdffed71309d1Patch, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2019/01/msg00020.htmlMailing List, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2021/09/msg00019.htmlMailing List, Third Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GK5T6JPMBHBPKS7HNGHYUUF4KKRMNSNU/Mailing List, Third Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OIFUL3CPM4S5TOXTTOCQ3CUZN6XCXUTR/Mailing List, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.