CVE-2016-3119: Mit Kerberos 5
Medium severity, CVSS 5.3. EPSS: 40% chance of exploitation in the next 30 days.
The process_db_args function in plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c in the LDAP KDB module in kadmind in MIT Kerberos 5 (aka krb5) through 1.13.4 and 1.14.x through 1.14.1 mishandles the DB argument, which allows remote authenticated users to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted request to modify a principal.
Affected products
- Mit Kerberos 5: version 1.0 only; version 1.0.6 only; version 1.1 only; version 1.1.1 only; version 1.2 only; version 1.2.1 only; …
- Opensuse Leap: version 42.1 only
- Opensuse Opensuse: version 13.2 only
Published 2016-03-26. Last modified 2026-06-17.