A null pointer de-reference was found in the way samba kerberos server handled missing sname in TGS-REQ (Ticket Granting Server - Request). An authenticated user could use this flaw to crash the samba server.
[ { "id": "CVE-2021-3671-5f6e87fc", "source": "https://github.com/heimdal/heimdal/commit/04171147948d0a3636bc6374181926f0fb2ec83a", "signature_type": "Line", "digest": { "threshold": 0.9, "line_hashes": [ "71814477620078668530731684481303091670", "284346098059572621942400253662874014995", "63355110677909982606625851675836965070", "200771017170665811656047669952130469804" ] }, "signature_version": "v1", "target": { "file": "kdc/krb5tgs.c" }, "deprecated": false }, { "id": "CVE-2021-3671-e212c18a", "source": "https://github.com/heimdal/heimdal/commit/04171147948d0a3636bc6374181926f0fb2ec83a", "signature_type": "Function", "digest": { "function_hash": "332444689167320886733846614105216309617", "length": 21025.0 }, "signature_version": "v1", "target": { "function": "tgs_build_reply", "file": "kdc/krb5tgs.c" }, "deprecated": false } ]