PT-2001-1056 · Mit · Krb5-Devel+5

CVE-2003-0041

·

Published

2001-08-02

·

Updated

2024-02-02

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions krb5-workstation versions 1.1.1 through 1.2.2 krb5-configs version 1.1.1 krb5-devel versions 1.1.1 through 1.2.2 krb5-server versions 1.1.1 through 1.2.2 krb5-libs version 1.1.1 krb5 version 1.1.1 through 1.2.2
Description The issue affects the Kerberos FTP client, allowing remote FTP sites to execute arbitrary code via a pipe (|) character in a filename that is retrieved by the client. This can lead to a violation of confidentiality, integrity, and availability of protected information. The exploitation of the vulnerabilities can be carried out remotely.
Recommendations For krb5-workstation versions 1.1.1 through 1.2.2, update to a version that is not affected by this issue. For krb5-configs version 1.1.1, update to a version that is not affected by this issue. For krb5-devel versions 1.1.1 through 1.2.2, update to a version that is not affected by this issue. For krb5-server versions 1.1.1 through 1.2.2, update to a version that is not affected by this issue. For krb5-libs version 1.1.1, update to a version that is not affected by this issue. For krb5 versions 1.1.1 through 1.2.2, update to a version that is not affected by this issue. As a temporary workaround, consider restricting the use of the Kerberos FTP client until a patch is available. Avoid using the Kerberos FTP client to retrieve files from untrusted remote FTP sites.

Fix

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-08132
BDU:2015-08133
BDU:2015-08135
BDU:2015-08136
BDU:2015-08137
BDU:2015-08139
BDU:2015-08142
BDU:2015-08143
BDU:2015-08145
BDU:2015-08146
CVE-2003-0041

Affected Products

Krb5
Krb5-Configs
Krb5-Devel
Krb5-Libs
Krb5-Server
Krb5-Workstation