Wind River Support Network

HomeDefectsLIN1018-1057
Acknowledged

LIN1018-1057 : Security Advisory - krb5 - CVE-2018-5709

Created: May 14, 2018    Updated: Sep 13, 2022
Found In Version: unknown
Severity: Standard
Applicable for: Wind River Linux LTS 18
Component/s: Userspace

Description

An issue was discovered in MIT Kerberos 5 (aka krb5) through 1.16. There is a variable dbentry->n_key_data in kadmin/dbutil/dump.c that can store 16-bit data but unknowingly the developer has assigned a u4 variable to it, which is for 32-bit data. An attacker can use this vulnerability to affect other artifacts of the database as we know that a Kerberos database dump file contains trusted data.

https://nvd.nist.gov/vuln/detail/CVE-2018-5709
Live chat
Online