The processdbargs function in plugins/kdb/ldap/libkdbldap/ldapprincipal2.c in the LDAP KDB module in kadmind in MIT Kerberos 5 (aka krb5) through 1.13.4 and 1.14.x through 1.14.1 mishandles the DB argument, which allows remote authenticated users to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted request to modify a principal.
{
"versions": [
{
"introduced": "0"
},
{
"last_affected": "1.0"
},
{
"introduced": "0"
},
{
"last_affected": "1.0.6"
},
{
"introduced": "0"
},
{
"last_affected": "1.1"
},
{
"introduced": "0"
},
{
"last_affected": "1.1.1"
},
{
"introduced": "0"
},
{
"last_affected": "1.2"
},
{
"introduced": "0"
},
{
"last_affected": "1.2-beta1"
},
{
"introduced": "0"
},
{
"last_affected": "1.2-beta2"
},
{
"introduced": "0"
},
{
"last_affected": "1.2.1"
},
{
"introduced": "0"
},
{
"last_affected": "1.2.2"
},
{
"introduced": "0"
},
{
"last_affected": "1.2.3"
},
{
"introduced": "0"
},
{
"last_affected": "1.2.4"
},
{
"introduced": "0"
},
{
"last_affected": "1.2.5"
},
{
"introduced": "0"
},
{
"last_affected": "1.2.6"
},
{
"introduced": "0"
},
{
"last_affected": "1.2.7"
},
{
"introduced": "0"
},
{
"last_affected": "1.2.8"
},
{
"introduced": "0"
},
{
"last_affected": "1.3"
},
{
"introduced": "0"
},
{
"last_affected": "1.3-alpha1"
},
{
"introduced": "0"
},
{
"last_affected": "1.3.1"
},
{
"introduced": "0"
},
{
"last_affected": "1.3.2"
},
{
"introduced": "0"
},
{
"last_affected": "1.3.3"
},
{
"introduced": "0"
},
{
"last_affected": "1.3.4"
},
{
"introduced": "0"
},
{
"last_affected": "1.3.5"
},
{
"introduced": "0"
},
{
"last_affected": "1.3.6"
},
{
"introduced": "0"
},
{
"last_affected": "1.4"
},
{
"introduced": "0"
},
{
"last_affected": "1.4.1"
},
{
"introduced": "0"
},
{
"last_affected": "1.4.2"
},
{
"introduced": "0"
},
{
"last_affected": "1.4.3"
},
{
"introduced": "0"
},
{
"last_affected": "1.4.4"
},
{
"introduced": "0"
},
{
"last_affected": "1.5"
},
{
"introduced": "0"
},
{
"last_affected": "1.5.1"
},
{
"introduced": "0"
},
{
"last_affected": "1.5.2"
},
{
"introduced": "0"
},
{
"last_affected": "1.5.3"
},
{
"introduced": "0"
},
{
"last_affected": "1.6"
},
{
"introduced": "0"
},
{
"last_affected": "1.6.1"
},
{
"introduced": "0"
},
{
"last_affected": "1.6.2"
},
{
"introduced": "0"
},
{
"last_affected": "1.7"
},
{
"introduced": "0"
},
{
"last_affected": "1.7.1"
},
{
"introduced": "0"
},
{
"last_affected": "1.8"
},
{
"introduced": "0"
},
{
"last_affected": "1.8.1"
},
{
"introduced": "0"
},
{
"last_affected": "1.8.2"
},
{
"introduced": "0"
},
{
"last_affected": "1.8.3"
},
{
"introduced": "0"
},
{
"last_affected": "1.8.4"
},
{
"introduced": "0"
},
{
"last_affected": "1.8.5"
},
{
"introduced": "0"
},
{
"last_affected": "1.8.6"
},
{
"introduced": "0"
},
{
"last_affected": "1.9"
},
{
"introduced": "0"
},
{
"last_affected": "1.9.1"
},
{
"introduced": "0"
},
{
"last_affected": "1.9.2"
},
{
"introduced": "0"
},
{
"last_affected": "1.9.3"
},
{
"introduced": "0"
},
{
"last_affected": "1.9.4"
},
{
"introduced": "0"
},
{
"last_affected": "1.10"
},
{
"introduced": "0"
},
{
"last_affected": "1.10.1"
},
{
"introduced": "0"
},
{
"last_affected": "1.10.2"
},
{
"introduced": "0"
},
{
"last_affected": "1.10.3"
},
{
"introduced": "0"
},
{
"last_affected": "1.10.4"
},
{
"introduced": "0"
},
{
"last_affected": "1.11"
},
{
"introduced": "0"
},
{
"last_affected": "1.11.1"
},
{
"introduced": "0"
},
{
"last_affected": "1.11.2"
},
{
"introduced": "0"
},
{
"last_affected": "1.11.3"
},
{
"introduced": "0"
},
{
"last_affected": "1.11.4"
},
{
"introduced": "0"
},
{
"last_affected": "1.11.5"
},
{
"introduced": "0"
},
{
"last_affected": "1.12"
},
{
"introduced": "0"
},
{
"last_affected": "1.12.1"
},
{
"introduced": "0"
},
{
"last_affected": "1.12.2"
},
{
"introduced": "0"
},
{
"last_affected": "1.12.3"
},
{
"introduced": "0"
},
{
"last_affected": "1.13"
},
{
"introduced": "0"
},
{
"last_affected": "1.13.1"
},
{
"introduced": "0"
},
{
"last_affected": "1.13.2"
},
{
"introduced": "0"
},
{
"last_affected": "1.13.3"
},
{
"introduced": "0"
},
{
"last_affected": "1.13.4"
},
{
"introduced": "0"
},
{
"last_affected": "1.14-alpha1"
},
{
"introduced": "0"
},
{
"last_affected": "1.14-beta1"
},
{
"introduced": "0"
},
{
"last_affected": "1.14-beta2"
},
{
"introduced": "0"
},
{
"last_affected": "1.14.1"
}
]
}"2026-04-11T03:43:44Z"
[
{
"id": "CVE-2016-3119-69632881",
"target": {
"file": "src/plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c",
"function": "process_db_args"
},
"deprecated": false,
"digest": {
"function_hash": "182495350258615914864353268036573521388",
"length": 1890.0
},
"signature_type": "Function",
"source": "https://github.com/krb5/krb5/commit/08c642c09c38a9c6454ab43a9b53b2a89b9eef99",
"signature_version": "v1"
},
{
"id": "CVE-2016-3119-cfff9bf4",
"target": {
"file": "src/plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c"
},
"deprecated": false,
"digest": {
"line_hashes": [
"24445841302081938003210580042065884435",
"313536785405792098730377874457343453112",
"48154515352199858062151739170266415443",
"270282537340677201132454849868526947895"
],
"threshold": 0.9
},
"signature_type": "Line",
"source": "https://github.com/krb5/krb5/commit/08c642c09c38a9c6454ab43a9b53b2a89b9eef99",
"signature_version": "v1"
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2016-3119.json"
[
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "42.1"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "13.2"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.14.0"
}
]
}
]