CVE Database
/

CVE-2016-3120

Back to search

CVE-2016-3120

Published: Aug 1, 2016

Modified: Aug 5, 2024

PUBLISHED

Description

The validate_as_request function in kdc_util.c in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) before 1.13.6 and 1.4.x before 1.14.3, when restrict_anonymous_to_tgt is enabled, uses an incorrect client data structure, which allows remote authenticated users to cause a denial of service (NULL pointer dereference and daemon crash) via an S4U2Self request.

VendorProductVersions

n/a

n/a

affected
n/a

References

92132
vdb-entry
x_refsource_BID
openSUSE-SU-2016:2268
vendor-advisory
x_refsource_SUSE
1036442
vdb-entry
x_refsource_SECTRACK
RHSA-2016:2591
vendor-advisory
x_refsource_REDHAT
FEDORA-2016-0674a3c372
vendor-advisory
x_refsource_FEDORA

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now