CVE-2018-5710: Mit Kerberos

Medium severity, CVSS 6.5. EPSS: 1.8% chance of exploitation in the next 30 days.

An issue was discovered in MIT Kerberos 5 (aka krb5) through 1.16. The pre-defined function "strlen" is getting a "NULL" string as a parameter value in plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c in the Key Distribution Center (KDC), which allows remote authenticated users to cause a denial of service (NULL pointer dereference) via a modified kadmin client.

Affected products

  • Mit Kerberos: up to and including 5-1.16

Published 2018-01-16. Last modified 2026-06-17.