PT-2001-1054 · Mit+1 · Krb5-Devel+6

Ken Raeburn

+2

·

Publicado

2001-08-02

·

Atualizado

2018-10-19

·

CVE-2003-0139

CVSS v2.0

10

Alta

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions krb5-workstation versions 1.1.1 through 1.2.7 krb5-devel versions 1.1.1 through 1.2.7 krb5-configs version 1.1.1 krb5-server versions 1.1.1 through 1.2.7 krb5-libs versions 1.1.1 through 1.2.7 krb5 versions 1.1.1 through 1.2.7
Description The issue concerns multiple vulnerabilities in the krb5 package of Red Hat Linux, which can lead to disruption of confidentiality, integrity, and availability of protected information. These vulnerabilities can be exploited remotely. Certain weaknesses in the implementation of version 4 of the Kerberos protocol in the krb5 distribution allow an attacker to create unauthorized tickets using a cut-and-paste attack and "ticket splicing" when triple-DES keys are used.
Recommendations For krb5-workstation versions 1.1.1 through 1.2.7, update to a version that contains a fix for this issue. For krb5-devel versions 1.1.1 through 1.2.7, update to a version that contains a fix for this issue. For krb5-configs version 1.1.1, update to a version that contains a fix for this issue. For krb5-server versions 1.1.1 through 1.2.7, update to a version that contains a fix for this issue. For krb5-libs versions 1.1.1 through 1.2.7, update to a version that contains a fix for this issue. For krb5 versions 1.1.1 through 1.2.7, update to a version that contains a fix for this issue. As a temporary workaround, consider restricting access to the vulnerable components until a patch is available.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

BDU:2015-08132
BDU:2015-08133
BDU:2015-08134
BDU:2015-08135
BDU:2015-08136
BDU:2015-08137
BDU:2015-08138
BDU:2015-08139
BDU:2015-08141
BDU:2015-08142
BDU:2015-08143
BDU:2015-08144
BDU:2015-08145
BDU:2015-08146
BDU:2015-08147
CVE-2003-0139
DSA-266
DSA-273

Produtos afetados

Red Hat
Krb5
Krb5-Configs
Krb5-Devel
Krb5-Libs
Krb5-Server
Krb5-Workstation