Wind River Support Network

HomeDefectsLIN10-3239
Not to be fixed

LIN10-3239 : Security Advisory - krb5 - CVE-2018-5709

Created: Jan 30, 2018    Updated: Dec 22, 2022
Resolved Date: Dec 22, 2022
Found In Version: 10.17.41.1
Severity: Standard
Applicable for: Wind River Linux LTS 17
Component/s: Userspace

Description

An issue was discovered in MIT Kerberos 5 (aka krb5) through 1.16. There is a variable dbentry->n_key_data in kadmin/dbutil/dump.c that can store 16-bit data but unknowingly the developer has assigned a u4 variable to it, which is for 32-bit data. An attacker can use this vulnerability to affect other artifacts of the database as we know that a Kerberos database dump file contains trusted data.

https://nvd.nist.gov/vuln/detail/CVE-2018-5709

CVEs


Live chat
Online