CVE-2016-3119
Published Mar 26, 2016
Last updated 5 years ago
Overview
- Description
- The process_db_args function in plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c in the LDAP KDB module in kadmind in MIT Kerberos 5 (aka krb5) through 1.13.4 and 1.14.x through 1.14.1 mishandles the DB argument, which allows remote authenticated users to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted request to modify a principal.
- Source
- cve@mitre.org
- NVD status
- Modified
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 3.0
- Type
- Primary
- Base score
- 5.3
- Impact score
- 3.6
- Exploitability score
- 1.6
- Vector string
- CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
- Severity
- MEDIUM
CVSS 2.0
- Type
- Primary
- Base score
- 3.5
- Impact score
- 2.9
- Exploitability score
- 6.8
- Vector string
- AV:N/AC:M/Au:S/C:N/I:N/A:P
Weaknesses
- nvd@nist.gov
- NVD-CWE-Other
Evaluator
- Comment
- <a href="http://cwe.mitre.org/data/definitions/476.html">CWE-476: NULL Pointer Dereference</a>
- Impact
- -
- Solution
- -
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:opensuse:leap:42.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "4863BE36-D16A-4D75-90D9-FD76DB5B48B7" }, { "criteria": "cpe:2.3:o:opensuse:opensuse:13.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "03117DF1-3BEC-4B8D-AD63-DBBDB2126081" } ], "operator": "OR" } ] }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:mit:kerberos_5:1.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "08FA60A9-10E1-4ACD-819C-17801FAD7671" }, { "criteria": "cpe:2.3:a:mit:kerberos_5:1.0.6:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E8973E93-0BBE-4BD3-9983-F6480FFEA228" }, { "criteria": "cpe:2.3:a:mit:kerberos_5:1.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "7A37987D-22F9-47AC-A07A-380F7E509BFE" }, { "criteria": "cpe:2.3:a:mit:kerberos_5:1.1.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E47F0770-67D7-42EE-A1AD-9D5B5E83BF2B" }, { "criteria": "cpe:2.3:a:mit:kerberos_5:1.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "BE8C0C82-749E-4837-88F8-FB56A753B094" }, { "criteria": "cpe:2.3:a:mit:kerberos_5:1.2:beta1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "4EA5E4B3-AD02-4E87-822B-8A6C91DA65FA" }, { "criteria": "cpe:2.3:a:mit:kerberos_5:1.2:beta2:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "1A0B70C1-476D-4FAF-BA96-CB3EB32B7BC5" }, { "criteria": "cpe:2.3:a:mit:kerberos_5:1.2.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "8AD672FA-918D-48CB-BC03-4E412AF0DCCC" }, { "criteria": "cpe:2.3:a:mit:kerberos_5:1.2.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D0B363A4-BB7A-48A2-AE6B-BD2DDD46E7CB" }, { "criteria": "cpe:2.3:a:mit:kerberos_5:1.2.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "74EF42A5-EC47-4475-81D6-FD1E9C2B8A3C" }, { "criteria": "cpe:2.3:a:mit:kerberos_5:1.2.4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "30F2CBEF-6FA1-4E07-8163-6AFEDC93FCE5" }, { "criteria": "cpe:2.3:a:mit:kerberos_5:1.2.5:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D133CB0D-8A54-4DAA-9FE8-0B367544DE65" }, { "criteria": "cpe:2.3:a:mit:kerberos_5:1.2.6:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "7B2C23BD-1995-4F09-B444-87DDDE21817E" }, { "criteria": "cpe:2.3:a:mit:kerberos_5:1.2.7:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "EEF118BE-6351-4768-A3F0-DFE0065273D9" }, { "criteria": "cpe:2.3:a:mit:kerberos_5:1.2.8:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "2574FC48-C80A-427A-AD12-42676D125D62" }, { "criteria": "cpe:2.3:a:mit:kerberos_5:1.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "7F01A83F-3BD1-4DED-979A-B4B6B23039FD" }, { "criteria": "cpe:2.3:a:mit:kerberos_5:1.3:alpha1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "6B1422F8-CC87-46EA-8649-A12D6E47335D" }, { "criteria": "cpe:2.3:a:mit:kerberos_5:1.3.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "ACEB5A36-8F72-417A-AC92-149612EC7BCB" }, { "criteria": "cpe:2.3:a:mit:kerberos_5:1.3.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "7B8704B5-F37B-4C61-A924-3774A29BFEB3" }, { "criteria": "cpe:2.3:a:mit:kerberos_5:1.3.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F953CEBA-BAC0-48DF-A3D0-1FABCC9963E2" }, { "criteria": "cpe:2.3:a:mit:kerberos_5:1.3.4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "ED81A044-8A7B-4EEF-A4B3-EA49D76FAAED" }, { "criteria": "cpe:2.3:a:mit:kerberos_5:1.3.5:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "30AA5727-BD83-45CF-B308-BA5F8A577B9D" }, { "criteria": "cpe:2.3:a:mit:kerberos_5:1.3.6:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "0E088E64-6FBD-4148-8F78-506364B7BB1E" }, { "criteria": "cpe:2.3:a:mit:kerberos_5:1.4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "52F0EECF-7787-442B-9888-D22F7D36C3DE" }, { "criteria": "cpe:2.3:a:mit:kerberos_5:1.4.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "EF344AED-BE00-4A9B-A9DE-C6FB0BEE4617" }, { "criteria": "cpe:2.3:a:mit:kerberos_5:1.4.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "567406CA-58D8-453E-B36E-6D1D2EFC8EB6" }, { "criteria": "cpe:2.3:a:mit:kerberos_5:1.4.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "7830E03F-A813-4E35-893E-BF27395CEFB3" }, { "criteria": "cpe:2.3:a:mit:kerberos_5:1.4.4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "7764411E-C056-4696-822E-235F2620FAC4" }, { "criteria": "cpe:2.3:a:mit:kerberos_5:1.5:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "4DD315AE-868B-4061-BF01-CDBF59B02499" }, { "criteria": "cpe:2.3:a:mit:kerberos_5:1.5.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B639DD5F-71C7-4D9B-BA5C-51CAF64140B6" }, { "criteria": "cpe:2.3:a:mit:kerberos_5:1.5.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "2B904DCE-D59F-45C7-A814-DE42CF02792D" }, { "criteria": "cpe:2.3:a:mit:kerberos_5:1.5.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "9957FE9E-1E89-4C27-852C-44F866A1834E" }, { "criteria": "cpe:2.3:a:mit:kerberos_5:1.6:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "2C382DAA-68D2-4DD9-BE29-8EEB0BAF1A7A" }, { "criteria": "cpe:2.3:a:mit:kerberos_5:1.6.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "73BB258E-51CF-4D12-836B-BCEA587A3F5F" }, { "criteria": "cpe:2.3:a:mit:kerberos_5:1.6.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F81DE01C-BA3B-40B4-BD85-17692F0AF8A8" }, { "criteria": "cpe:2.3:a:mit:kerberos_5:1.7:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "DFB1190E-BE7A-4C6B-862D-D5747C64E980" }, { "criteria": "cpe:2.3:a:mit:kerberos_5:1.7.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "4B09C090-B842-43C7-B8A6-DBF63D80FEC3" }, { "criteria": "cpe:2.3:a:mit:kerberos_5:1.8:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "36823B2B-5C72-4FF3-9301-FB263EB8CE09" }, { "criteria": "cpe:2.3:a:mit:kerberos_5:1.8.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "59AFA33E-FEBC-45F5-9EC6-8AA363163FB5" }, { "criteria": "cpe:2.3:a:mit:kerberos_5:1.8.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "04D83332-B2FD-4E86-A76C-C3F1CD3B3A31" }, { "criteria": "cpe:2.3:a:mit:kerberos_5:1.8.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "758A0011-20ED-414A-9DF3-50A161DF8BC2" }, { "criteria": "cpe:2.3:a:mit:kerberos_5:1.8.4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "7768AED0-AE4C-4D4E-8D5D-5B618AB82966" }, { "criteria": "cpe:2.3:a:mit:kerberos_5:1.8.5:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "534104C5-966E-4740-A354-4F6C210FF25B" }, { "criteria": "cpe:2.3:a:mit:kerberos_5:1.8.6:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "78AF5659-C0E3-49C4-9CA7-FC3917C8AC49" }, { "criteria": "cpe:2.3:a:mit:kerberos_5:1.9:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "86738633-C081-4440-9F75-A775D6DF2228" }, { "criteria": "cpe:2.3:a:mit:kerberos_5:1.9.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C7BCFFEE-EA7A-4F26-97AA-31128A179745" }, { "criteria": "cpe:2.3:a:mit:kerberos_5:1.9.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "91A2D7F5-EBDE-4000-AC78-8DD6472E685A" }, { "criteria": "cpe:2.3:a:mit:kerberos_5:1.9.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "8E92BFA5-723E-4843-A8D8-BC1D32F34569" }, { "criteria": "cpe:2.3:a:mit:kerberos_5:1.9.4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "34C27198-9B55-42FB-AA21-D8B4EB60D926" }, { "criteria": "cpe:2.3:a:mit:kerberos_5:1.10:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "FC504264-A9E9-4433-B7AA-6D5015A93FF3" }, { "criteria": "cpe:2.3:a:mit:kerberos_5:1.10.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "77FA352F-520C-4C05-AD52-FC8586DB16B1" }, { "criteria": "cpe:2.3:a:mit:kerberos_5:1.10.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "9FFB18F7-CB08-4AE4-9DEC-55D047819A0A" }, { "criteria": "cpe:2.3:a:mit:kerberos_5:1.10.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "637E858A-7C16-490C-99A8-F46440E5F504" }, { "criteria": "cpe:2.3:a:mit:kerberos_5:1.10.4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "22840B84-2EA4-4E96-A8D8-154AAEADB806" }, { "criteria": "cpe:2.3:a:mit:kerberos_5:1.11:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "2D554BDC-CD7D-4572-B1E8-5F627F2C5916" }, { "criteria": "cpe:2.3:a:mit:kerberos_5:1.11.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "65BCD38A-33AD-4FD7-AF5B-8470B24C4139" }, { "criteria": "cpe:2.3:a:mit:kerberos_5:1.11.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E11F9209-799A-428B-9513-DBD0F19C7BF4" }, { "criteria": "cpe:2.3:a:mit:kerberos_5:1.11.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "1DA40FAA-B858-4282-8438-247E99FBB002" }, { "criteria": "cpe:2.3:a:mit:kerberos_5:1.11.4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "65795542-D886-46C4-8ECB-4630078DF66A" }, { "criteria": "cpe:2.3:a:mit:kerberos_5:1.11.5:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D0A4C436-C3D7-469E-8895-8EEC9569EE86" }, { "criteria": "cpe:2.3:a:mit:kerberos_5:1.12:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "79A9FAE9-7219-4D6A-9E94-FFE20223537D" }, { "criteria": "cpe:2.3:a:mit:kerberos_5:1.12.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "EA68BC90-FCFC-4C9B-8574-9029DB2358E9" }, { "criteria": "cpe:2.3:a:mit:kerberos_5:1.12.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "9D0A28CB-173D-4676-B083-E3718213B840" }, { "criteria": "cpe:2.3:a:mit:kerberos_5:1.12.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "AA3D2861-7EB7-4984-AC92-989B427BDB58" }, { "criteria": "cpe:2.3:a:mit:kerberos_5:1.13:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "169D00BD-344F-453C-BE7C-9DF0740080BB" }, { "criteria": "cpe:2.3:a:mit:kerberos_5:1.13.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "765B3248-A524-4A79-858C-E787C1C1599E" }, { "criteria": "cpe:2.3:a:mit:kerberos_5:1.13.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "BF1BB0AB-2C22-49F9-9D2A-074D2F711BA8" }, { "criteria": "cpe:2.3:a:mit:kerberos_5:1.13.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C8EC001E-9507-410D-836F-93002789D574" }, { "criteria": "cpe:2.3:a:mit:kerberos_5:1.13.4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "CC0939BF-9ACB-41A7-9B48-0FBF1176C8CB" }, { "criteria": "cpe:2.3:a:mit:kerberos_5:1.14:alpha1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "EC81822F-DC8C-4889-AD53-33216B66A109" }, { "criteria": "cpe:2.3:a:mit:kerberos_5:1.14:beta1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C1B23EE0-35EB-46FC-8620-AC0059498D9B" }, { "criteria": "cpe:2.3:a:mit:kerberos_5:1.14:beta2:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "70831CB8-695D-45E8-A829-2E888823E8A5" }, { "criteria": "cpe:2.3:a:mit:kerberos_5:1.14.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "94DADC6D-0449-40C1-85C6-109CFB8EDFAB" }, { "criteria": "cpe:2.3:a:mit:kerberos_5:1.14.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E650B5A3-99CA-491B-A1FB-259EF548D92E" } ], "operator": "OR" } ] } ]