Wind River Support Network

HomeDefectsLIN7-9457
Acknowledged

LIN7-9457 : Security Advisory - krb5 - CVE-2018-5709

Created: Jan 30, 2018    Updated: Sep 11, 2018
Found In Version: 7.0.0.27
Severity: Standard
Applicable for: Wind River Linux 7
Component/s: Userspace

Description

An issue was discovered in MIT Kerberos 5 (aka krb5) through 1.16. There is a variable dbentry->n_key_data in kadmin/dbutil/dump.c that can store 16-bit data but unknowingly the developer has assigned a u4 variable to it, which is for 32-bit data. An attacker can use this vulnerability to affect other artifacts of the database as we know that a Kerberos database dump file contains trusted data.

https://nvd.nist.gov/vuln/detail/CVE-2018-5709

CVEs


Live chat
Online