5.3

CVE-2016-3119

The process_db_args function in plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c in the LDAP KDB module in kadmind in MIT Kerberos 5 (aka krb5) through 1.13.4 and 1.14.x through 1.14.1 mishandles the DB argument, which allows remote authenticated users to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted request to modify a principal.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
OpensuseLeap Version42.1
OpensuseOpensuse Version13.2
MitKerberos 5 Version1.0
MitKerberos 5 Version1.0.6
MitKerberos 5 Version1.1
MitKerberos 5 Version1.1.1
MitKerberos 5 Version1.2
MitKerberos 5 Version1.2 Updatebeta1
MitKerberos 5 Version1.2 Updatebeta2
MitKerberos 5 Version1.2.1
MitKerberos 5 Version1.2.2
MitKerberos 5 Version1.2.3
MitKerberos 5 Version1.2.4
MitKerberos 5 Version1.2.5
MitKerberos 5 Version1.2.6
MitKerberos 5 Version1.2.7
MitKerberos 5 Version1.2.8
MitKerberos 5 Version1.3
MitKerberos 5 Version1.3 Updatealpha1
MitKerberos 5 Version1.3.1
MitKerberos 5 Version1.3.2
MitKerberos 5 Version1.3.3
MitKerberos 5 Version1.3.4
MitKerberos 5 Version1.3.5
MitKerberos 5 Version1.3.6
MitKerberos 5 Version1.4
MitKerberos 5 Version1.4.1
MitKerberos 5 Version1.4.2
MitKerberos 5 Version1.4.3
MitKerberos 5 Version1.4.4
MitKerberos 5 Version1.5
MitKerberos 5 Version1.5.1
MitKerberos 5 Version1.5.2
MitKerberos 5 Version1.5.3
MitKerberos 5 Version1.6
MitKerberos 5 Version1.6.1
MitKerberos 5 Version1.6.2
MitKerberos 5 Version1.7
MitKerberos 5 Version1.7.1
MitKerberos 5 Version1.8
MitKerberos 5 Version1.8.1
MitKerberos 5 Version1.8.2
MitKerberos 5 Version1.8.3
MitKerberos 5 Version1.8.4
MitKerberos 5 Version1.8.5
MitKerberos 5 Version1.8.6
MitKerberos 5 Version1.9
MitKerberos 5 Version1.9.1
MitKerberos 5 Version1.9.2
MitKerberos 5 Version1.9.3
MitKerberos 5 Version1.9.4
MitKerberos 5 Version1.10
MitKerberos 5 Version1.10.1
MitKerberos 5 Version1.10.2
MitKerberos 5 Version1.10.3
MitKerberos 5 Version1.10.4
MitKerberos 5 Version1.11
MitKerberos 5 Version1.11.1
MitKerberos 5 Version1.11.2
MitKerberos 5 Version1.11.3
MitKerberos 5 Version1.11.4
MitKerberos 5 Version1.11.5
MitKerberos 5 Version1.12
MitKerberos 5 Version1.12.1
MitKerberos 5 Version1.12.2
MitKerberos 5 Version1.12.3
MitKerberos 5 Version1.13
MitKerberos 5 Version1.13.1
MitKerberos 5 Version1.13.2
MitKerberos 5 Version1.13.3
MitKerberos 5 Version1.13.4
MitKerberos 5 Version1.14 Updatealpha1
MitKerberos 5 Version1.14 Updatebeta1
MitKerberos 5 Version1.14 Updatebeta2
MitKerberos 5 Version1.14.0
MitKerberos 5 Version1.14.1
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 5.72% 0.901
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5.3 1.6 3.6
CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
nvd@nist.gov 3.5 6.8 2.9
AV:N/AC:M/Au:S/C:N/I:N/A:P