Back

HIGH

krb5: integer overflow in dbentry->n_key_data in kadmin/dbutil/dump.c

Published Jan 16, 2018

Description

An issue was discovered in MIT Kerberos 5 (aka krb5) through 1.16. There is a variable "dbentry->n_key_data" in kadmin/dbutil/dump.c that can store 16-bit data but unknowingly the developer has assigned a "u4" variable to it, which is for 32-bit data. An attacker can use this vulnerability to affect other artifacts of the database as we know that a Kerberos database dump file contains trusted data.

Affected products

Remediation

Red Hat statement

This is essentially an integer truncation issue, and not an integer overflow. We have determined that this should not affect any other data allocated close to the 16-bit integer in question "dbentry-> n_key_data". Red Hat Product Security does not consider this issue as a security flaw.

Metrics

References (6)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jan 16, 2018
Updated Aug 5, 2024
Reserved Jan 16, 2018
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date Jan 15, 2018