Denial of Service Vulnerability in MIT Kerberos 5 Software
CVE-2016-3120
6.5MEDIUM
What is CVE-2016-3120?
The validate_as_request function in the Key Distribution Center (KDC) for MIT Kerberos 5 versions prior to 1.13.6 and 1.4.x before 1.14.3 is susceptible to a denial of service attack. When the restrict_anonymous_to_tgt feature is enabled, an incorrect client data structure is utilized, which permits remote authenticated users to exploit this issue. This exploitation can lead to a NULL pointer dereference, crashing the daemon and disrupting the service.
