CVE-2018-5730
Summary
| CVE | CVE-2018-5730 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-03-06 20:29:00 UTC |
| Updated | 2023-11-07 02:58:00 UTC |
| Description | MIT krb5 1.6 or later allows an authenticated kadmin with permission to add principals to an LDAP Kerberos database to circumvent a DN containership check by supplying both a "linkdn" and "containerdn" database argument, or by supplying a DN string which is a left extension of a container DN string but is not hierarchically within the container DN. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| [SECURITY] Fedora 26 Update: krb5-1.15.2-7.fc26 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| [SECURITY] Fedora 26 Update: krb5-1.15.2-7.fc26 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
Third Party Advisory |
| [SECURITY] [DLA 2771-1] krb5 security update |
MLIST |
lists.debian.org |
|
| 1551082 – (CVE-2018-5730) CVE-2018-5730 krb5: DN container check bypass by supplying special crafted data |
CONFIRM |
bugzilla.redhat.com |
Issue Tracking, Patch, Third Party Advisory |
| Fix flaws in LDAP DN checking · krb5/krb5@e1caf6f · GitHub |
CONFIRM |
github.com |
Patch, Third Party Advisory |
| [SECURITY] Fedora 27 Update: krb5-1.15.2-7.fc27 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| [SECURITY] Fedora 27 Update: krb5-1.15.2-7.fc27 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
Third Party Advisory |
| #891869 - krb5: CVE-2018-5729 CVE-2018-5730 - Debian Bug report logs |
CONFIRM |
bugs.debian.org |
Third Party Advisory |
| [SECURITY] [DLA 1643-1] krb5 security update |
MLIST |
lists.debian.org |
Mailing List, Third Party Advisory |
| Red Hat Customer Portal |
REDHAT |
access.redhat.com |
Third Party Advisory |
| Red Hat Customer Portal |
REDHAT |
access.redhat.com |
Third Party Advisory |
| MIT Kerberos Lets Remote Authenticated Users Gain Elevated Privileges in Certain Cases - SecurityTracker |
SECTRACK |
www.securitytracker.com |
Third Party Advisory, VDB Entry |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 178852 Debian Security Update for krb5 (DLA 2771-1)