← Volver a CVEs
CVE-2016-3119
N/ADescripcion
The process_db_args function in plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c in the LDAP KDB module in kadmind in MIT Kerberos 5 (aka krb5) through 1.13.4 and 1.14.x through 1.14.1 mishandles the DB argument, which allows remote authenticated users to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted request to modify a principal.
Detalles CVE
Puntuacion CVSS v3.1N/A
Publicado3/26/2016
Ultima modificacion5/6/2026
Fuentenvd
Avistamientos honeypot0
Productos afectados
mit:kerberos_5opensuse:leapopensuse:opensuse
Referencias
http://rhn.redhat.com/errata/RHSA-2016-2591.html(cve@mitre.org)
http://www.securityfocus.com/bid/85392(cve@mitre.org)
http://www.securitytracker.com/id/1035399(cve@mitre.org)
http://lists.opensuse.org/opensuse-updates/2016-04/msg00007.html(af854a3a-2127-422b-91ae-364da2661108)
http://lists.opensuse.org/opensuse-updates/2016-04/msg00055.html(af854a3a-2127-422b-91ae-364da2661108)
http://rhn.redhat.com/errata/RHSA-2016-2591.html(af854a3a-2127-422b-91ae-364da2661108)
http://www.securityfocus.com/bid/85392(af854a3a-2127-422b-91ae-364da2661108)
http://www.securitytracker.com/id/1035399(af854a3a-2127-422b-91ae-364da2661108)
https://github.com/krb5/krb5/commit/08c642c09c38a9c6454ab43a9b53b2a89b9eef99(af854a3a-2127-422b-91ae-364da2661108)
https://lists.debian.org/debian-lts-announce/2018/01/msg00040.html(af854a3a-2127-422b-91ae-364da2661108)
Correlaciones IOC
Sin correlaciones registradas
This product uses data from the NVD API but is not endorsed or certified by the NVD.