The processdbargs function in plugins/kdb/ldap/libkdbldap/ldapprincipal2.c in the LDAP KDB module in kadmind in MIT Kerberos 5 (aka krb5) through 1.13.4 and 1.14.x through 1.14.1 mishandles the DB argument, which allows remote authenticated users to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted request to modify a principal.
[
{
"id": "CVE-2016-3119-69632881",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Function",
"digest": {
"function_hash": "182495350258615914864353268036573521388",
"length": 1890.0
},
"target": {
"file": "src/plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c",
"function": "process_db_args"
},
"source": "https://github.com/krb5/krb5/commit/08c642c09c38a9c6454ab43a9b53b2a89b9eef99"
},
{
"id": "CVE-2016-3119-cfff9bf4",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Line",
"digest": {
"line_hashes": [
"24445841302081938003210580042065884435",
"313536785405792098730377874457343453112",
"48154515352199858062151739170266415443",
"270282537340677201132454849868526947895"
],
"threshold": 0.9
},
"target": {
"file": "src/plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c"
},
"source": "https://github.com/krb5/krb5/commit/08c642c09c38a9c6454ab43a9b53b2a89b9eef99"
}
]