CVE-2016-3119

medium
Published 2016-03-26 ยท Modified 2026-05-06
CVSS v3
5.3
CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
CVSS v4 NEW
โ€”
not yet in upstream
VIR risk
5.3

Description

The process_db_args function in plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c in the LDAP KDB module in kadmind in MIT Kerberos 5 (aka krb5) through 1.13.4 and 1.14.x through 1.14.1 mishandles the DB argument, which allows remote authenticated users to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted request to modify a principal.

Predictions

Exploit likelihood
63%
Patch ETA
โ€”

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

No mitigations published for this CVE yet.

The vendor-content worker queues fetches as references arrive (check back in a few minutes). Or โ€” if you've already worked around this in production โ€” publish your fix to the community-verified tier.

โœš Propose a mitigation on Community โ†’ Mitigations published via the community go through AI scoring + 2 human reviewers + 7-day silent objection window before landing here with source_tier=community-verified.

OS impact

OSVersionStatusFixed in
debian debianbookwormfixed1.14.2+dfsg-1
debian debianbullseyefixed1.14.2+dfsg-1
debian debianforkyfixed1.14.2+dfsg-1
debian debiansidfixed1.14.2+dfsg-1
debian debiantrixiefixed1.14.2+dfsg-1
suse suse42.1affected
suse suse13.2affected

Application impact

VendorProductVersionsFixed
mitkerberos_51.0
mitkerberos_51.0.6
mitkerberos_51.1
mitkerberos_51.1.1
mitkerberos_51.2
mitkerberos_51.2.1
mitkerberos_51.2.2
mitkerberos_51.2.3
mitkerberos_51.2.4
mitkerberos_51.2.5
mitkerberos_51.2.6
mitkerberos_51.2.7
mitkerberos_51.2.8
mitkerberos_51.3
mitkerberos_51.3.1
mitkerberos_51.3.2
mitkerberos_51.3.3
mitkerberos_51.3.4
mitkerberos_51.3.5
mitkerberos_51.3.6
mitkerberos_51.4
mitkerberos_51.4.1
mitkerberos_51.4.2
mitkerberos_51.4.3
mitkerberos_51.4.4
mitkerberos_51.5
mitkerberos_51.5.1
mitkerberos_51.5.2
mitkerberos_51.5.3
mitkerberos_51.6
mitkerberos_51.6.1
mitkerberos_51.6.2
mitkerberos_51.7
mitkerberos_51.7.1
mitkerberos_51.8
mitkerberos_51.8.1
mitkerberos_51.8.2
mitkerberos_51.8.3
mitkerberos_51.8.4
mitkerberos_51.8.5
mitkerberos_51.8.6
mitkerberos_51.9
mitkerberos_51.9.1
mitkerberos_51.9.2
mitkerberos_51.9.3
mitkerberos_51.9.4
mitkerberos_51.10
mitkerberos_51.10.1
mitkerberos_51.10.2
mitkerberos_51.10.3
mitkerberos_51.10.4
mitkerberos_51.11
mitkerberos_51.11.1
mitkerberos_51.11.2
mitkerberos_51.11.3
mitkerberos_51.11.4
mitkerberos_51.11.5
mitkerberos_51.12
mitkerberos_51.12.1
mitkerberos_51.12.2
mitkerberos_51.12.3
mitkerberos_51.13
mitkerberos_51.13.1
mitkerberos_51.13.2
mitkerberos_51.13.3
mitkerberos_51.13.4
mitkerberos_51.14
mitkerberos_51.14.0
mitkerberos_51.14.1

References

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.