MGASA-2018-0155

Source
https://advisories.mageia.org/MGASA-2018-0155.html
Import Source
https://advisories.mageia.org/MGASA-2018-0155.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2018-0155
Related
Published
2018-03-01T21:27:52Z
Modified
2018-03-01T21:11:41Z
Summary
Updated krb5 packages fix security vulnerabilities
Details

Updated krb5 packages fix security vulnerabilities:

An issue was discovered in MIT Kerberos 5 (aka krb5) through 1.16. The pre-defined function "strlen" is getting a "NULL" string as a parameter value in plugins/kdb/ldap/libkdbldap/ldapprincipal2.c in the Key Distribution Center (KDC), which allows remote authenticated users to cause a denial of service (NULL pointer dereference) via a modified kadmin client (CVE-2018-5710, CVE-2018-5729, CVE-2018-5730).

References
Credits

Affected packages

Mageia:6 / krb5

Package

Name
krb5
Purl
pkg:rpm/mageia/krb5?distro=mageia-6

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.15.1-2.3.mga6

Ecosystem specific

{
    "section": "core"
}