Back

MEDIUM

krb5: null dereference in kadmind or DN container check bypass by supplying special crafted data

Published Mar 6, 2018

Description

MIT krb5 1.6 or later allows an authenticated kadmin with permission to add principals to an LDAP Kerberos database to cause a denial of service (NULL pointer dereference) or bypass a DN container check by supplying tagged data that is internal to the database module.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (13)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Mar 6, 2018
Updated Aug 5, 2024
Reserved Jan 16, 2018
NVD
Status Undergoing Analysis
Modified Jun 17, 2026
Red Hat
Severity Low
Public date Mar 1, 2018