{"id":"MGASA-2016-0123","summary":"Updated krb5 packages fix security vulnerability","details":"It was reported that in all versions of MIT krb5, an authenticated\nattacker with permission to modify a principal entry can cause kadmind to\ndereference a null pointer by supplying an empty DB argument to the\nmodify_principal command, if kadmind is configured to use the LDAP KDB\nmodule (CVE-2016-3119).\n\nThe krb5 package has been updated to version 1.12.5 and patched to fix\nthis issue and other bugs.\n","modified":"2026-04-16T06:25:59.265316118Z","published":"2016-03-25T06:38:37Z","upstream":["CVE-2016-3119"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2016-0123.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=18058"},{"type":"WEB","url":"http://web.mit.edu/kerberos/krb5-1.12/krb5-1.12.5.html"},{"type":"WEB","url":"https://lists.fedoraproject.org/pipermail/package-announce/2016-March/179220.html"}],"affected":[{"package":{"name":"krb5","ecosystem":"Mageia:5","purl":"pkg:rpm/mageia/krb5?arch=source&distro=mageia-5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.12.5-1.mga5"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2016-0123.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}