CVE-2018-5730

Publication date 6 March 2018

Last updated 25 August 2025


Ubuntu priority

Cvss 3 Severity Score

3.8 · Low

Score breakdown

Description

MIT krb5 1.6 or later allows an authenticated kadmin with permission to add principals to an LDAP Kerberos database to circumvent a DN containership check by supplying both a "linkdn" and "containerdn" database argument, or by supplying a DN string which is a left extension of a container DN string but is not hierarchically within the container DN.

From the Ubuntu Security Team

It was discovered that Kerberos incorrectly handled certain database arguments. A remote authenticated attacker could possibly use this issue to obtain sensitive information.

Status

Package Ubuntu Release Status
krb5 21.04 hirsute
Not affected
20.10 groovy
Not affected
20.04 LTS focal
Not affected
19.10 eoan
Not affected
19.04 disco
Not affected
18.10 cosmic
Fixed 1.16-2ubuntu1.1
18.04 LTS bionic
Fixed 1.16-2ubuntu0.1
17.10 artful Ignored end of life
16.04 LTS xenial
Fixed 1.13.2+dfsg-5ubuntu2.1
14.04 LTS trusty
Fixed 1.12+dfsg-2ubuntu5.4

Severity score breakdown

CVSS version: CVSS v3.0

Base score 3.8 · Low

Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N


Access our resources on patching vulnerabilities