Описание
Security update for krb5
This update for krb5 fixes the following issues:
Security issues fixed:
- CVE-2018-5729, CVE-2018-5730: Fixed multiple flaws in LDAP DN checking (bsc#1083926, bsc#1083927)
This update was imported from the SUSE:SLE-15:Update update project.
Список пакетов
openSUSE Leap 15.0
Ссылки
- E-Mail link for openSUSE-SU-2019:0139-1
- SUSE Security Ratings
- SUSE Bug 1083926
- SUSE Bug 1083927
- SUSE CVE CVE-2018-5729 page
- SUSE CVE CVE-2018-5730 page
Описание
MIT krb5 1.6 or later allows an authenticated kadmin with permission to add principals to an LDAP Kerberos database to cause a denial of service (NULL pointer dereference) or bypass a DN container check by supplying tagged data that is internal to the database module.
Затронутые продукты
Ссылки
- CVE-2018-5729
- SUSE Bug 1076211
- SUSE Bug 1083926
- SUSE Bug 1122468
Описание
MIT krb5 1.6 or later allows an authenticated kadmin with permission to add principals to an LDAP Kerberos database to circumvent a DN containership check by supplying both a "linkdn" and "containerdn" database argument, or by supplying a DN string which is a left extension of a container DN string but is not hierarchically within the container DN.
Затронутые продукты
Ссылки
- CVE-2018-5730
- SUSE Bug 1076211
- SUSE Bug 1083927
- SUSE Bug 1122468