VDB
ALPINE-CVE-2016-3119
ALPINE-CVE-2016-3119
PUBLISHED
CVSS 5.300000190734863 MEDIUM
The process_db_args function in plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c in the LDAP KDB module in kadmind in MIT Kerberos 5 (aka krb5) through 1.13.4 and 1.14.x through 1.14.1 mishandles the DB argument, which allows remote authenticated users to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted request to modify a principal.
Risk Scores
CVSS v3.0
5.300000190734863
CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Alpine:v3.4 | krb5 | 1.11-r1, 1.11-r2, 1.11.2-r0 |
Timeline
- Mar 26, 2016 CVE Published
- Nov 19, 2025 CVE Updated
- Apr 30, 2026 Distribution Patch