PT-2010-1102 · Mit · Mit Kerberos 5

Publicado

2010-12-02

·

Atualizado

2024-06-15

·

CVE-2010-4021

CVSS v2.0

10

Alta

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions MIT Kerberos 5 versions 1.7 through 1.9.2-r1
Description The Key Distribution Center (KDC) in MIT Kerberos 5 does not properly restrict the use of TGT credentials for armoring TGS requests, which might allow remote authenticated users to impersonate a client by rewriting an inner request. Multiple vulnerabilities in the mit-krb5 package can lead to breaches of confidentiality, integrity, and availability of protected information, and can be exploited remotely.
Recommendations For versions 1.7 through 1.9.2-r1, update to a version later than 1.9.2-r1 to resolve the issue. At the moment, there is no information about other specific fixes for this vulnerability.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-09426
CVE-2010-4021
OPENSUSE-SU-2024:10004-1

Produtos afetados

Mit Kerberos 5