A null pointer de-reference was found in the way samba kerberos server handled missing sname in TGS-REQ (Ticket Granting Server - Request). An authenticated user could use this flaw to crash the samba server.
[
{
"source": "https://github.com/heimdal/heimdal/commit/04171147948d0a3636bc6374181926f0fb2ec83a",
"target": {
"file": "kdc/krb5tgs.c"
},
"deprecated": false,
"signature_version": "v1",
"id": "CVE-2021-3671-5f6e87fc",
"digest": {
"threshold": 0.9,
"line_hashes": [
"71814477620078668530731684481303091670",
"284346098059572621942400253662874014995",
"63355110677909982606625851675836965070",
"200771017170665811656047669952130469804"
]
},
"signature_type": "Line"
},
{
"source": "https://github.com/heimdal/heimdal/commit/04171147948d0a3636bc6374181926f0fb2ec83a",
"target": {
"function": "tgs_build_reply",
"file": "kdc/krb5tgs.c"
},
"deprecated": false,
"signature_version": "v1",
"id": "CVE-2021-3671-e212c18a",
"digest": {
"length": 21025.0,
"function_hash": "332444689167320886733846614105216309617"
},
"signature_type": "Function"
}
]