CVE-2016-3119

Loading...

General

Score:3.5/10.0
Severity:Low
Category:N/A

Impact Metrics

Confidentiality:None
Integrity:None
Availability:Partial

Exploitability Metrics

Access Vector:Network
Access Complexity:Medium
Authentication:Single

Relative vulnerabilities

CVE-2013-1418, CVE-2014-5351, CVE-2014-5353, CVE-2014-5355, CVE-2016-3120

Published on 26/03/16 - Updated on 04/02/18

Description

The process_db_args function in plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c in the LDAP KDB module in kadmind in MIT Kerberos 5 (aka krb5) through 1.13.4 and 1.14.x through 1.14.1 mishandles the DB argument, which allows remote authenticated users to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted request to modify a principal.

Category:

There is insufficient information about the issue to classify it; details are unknown or unspecified.

Security Notices

US National Vulnerability DatabaseCVE-2016-3119
Amazon Linux ALAS-2017-793
CentOS CESA-2016:2591
Debian LTSDLA-1265-1
Oracle Linux ELSA-2016-2591
Redhat RHSA-2016:2591
SUSE SUSE-SU-2016:0994, SUSE-SU-2016:1088

Exploits

No exploits available for this CVE in our database.

Relative technologies

VendorProduct
mitkerberos
novellleap
opensuse_projectopensuse

Share this vulnerability with:

Twitter Facebook LinkedIn Mail