PT-2001-1057 · Mit · Krb5-Devel+5
Greg Pryzby
+1
·
Published
2001-08-02
·
Updated
2020-01-21
·
CVE-2003-0058
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
krb5-workstation versions 1.1.1 through 1.2.2
krb5-devel versions 1.1.1 through 1.2.2
krb5-configs version 1.1.1
krb5-server versions 1.1.1 through 1.2.2
krb5-libs version 1.1.1
MIT Kerberos V5 Key Distribution Center (KDC) versions prior to 1.2.5
Description
The issue affects the confidentiality, integrity, and availability of protected information. Exploitation of the vulnerabilities can be done remotely. The MIT Kerberos V5 Key Distribution Center (KDC) is vulnerable to a denial of service (crash) on KDCs within the same realm via a certain protocol request that causes a null dereference.
Recommendations
For krb5-workstation versions 1.1.1 through 1.2.2, update to a version later than 1.2.2.
For krb5-devel versions 1.1.1 through 1.2.2, update to a version later than 1.2.2.
For krb5-configs version 1.1.1, update to a version later than 1.1.1.
For krb5-server versions 1.1.1 through 1.2.2, update to a version later than 1.2.2.
For krb5-libs version 1.1.1, update to a version later than 1.1.1.
For MIT Kerberos V5 Key Distribution Center (KDC) versions prior to 1.2.5, update to version 1.2.5 or later.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Mit Kerberos V5 Key Distribution Center
Krb5-Configs
Krb5-Devel
Krb5-Libs
Krb5-Server
Krb5-Workstation