PT-2001-1058 · Mit+1 · Krb5-Devel+7

Gerald Britton

+1

·

Publicado

2001-08-02

·

Atualizado

2020-01-21

·

CVE-2003-0059

CVSS v2.0

10

Alta

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions MIT Kerberos V5 versions prior to 1.2.5 krb5-workstation versions 1.1.1 through 1.2.2 krb5-configs version 1.1.1 krb5-devel versions 1.1.1 through 1.2.2 krb5-server versions 1.1.1 through 1.2.2 krb5-libs version 1.1.1 krb5 version 1.1.1 through 1.2.2
Description The issue involves multiple vulnerabilities in the krb5 packages of Red Hat Linux, which can lead to breaches of confidentiality, integrity, and availability of protected information. These vulnerabilities can be exploited remotely. The vulnerabilities in the MIT Kerberos V5 library, specifically in the chk trans.c file, allow users from one realm to impersonate users in other realms that have the same inter-realm keys.
Recommendations For MIT Kerberos V5 versions prior to 1.2.5, update to version 1.2.5 or later. For krb5-workstation versions 1.1.1 through 1.2.2, update to a version later than 1.2.2. For krb5-configs version 1.1.1, update to a version later than 1.1.1. For krb5-devel versions 1.1.1 through 1.2.2, update to a version later than 1.2.2. For krb5-server versions 1.1.1 through 1.2.2, update to a version later than 1.2.2. For krb5-libs version 1.1.1, update to a version later than 1.1.1. For krb5 versions 1.1.1 through 1.2.2, update to a version later than 1.2.2.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

BDU:2015-08132
BDU:2015-08133
BDU:2015-08135
BDU:2015-08136
BDU:2015-08137
BDU:2015-08139
BDU:2015-08142
BDU:2015-08143
BDU:2015-08145
BDU:2015-08146
CVE-2003-0059

Produtos afetados

Mit Kerberos 5
Red Hat
Krb5
Krb5-Configs
Krb5-Devel
Krb5-Libs
Krb5-Server
Krb5-Workstation