MIT krb5 1.6 or later allows an authenticated kadmin with...
Moderate severity
Unreviewed
Published
May 13, 2022
to the GitHub Advisory Database
•
Updated May 23, 2024
Description
Published by the National Vulnerability Database
Mar 6, 2018
Published to the GitHub Advisory Database
May 13, 2022
Last updated
May 23, 2024
MIT krb5 1.6 or later allows an authenticated kadmin with permission to add principals to an LDAP Kerberos database to cause a denial of service (NULL pointer dereference) or bypass a DN container check by supplying tagged data that is internal to the database module.
References