PT-2010-1095 · Mit · Mit-Krb5+1
Emmanuel Bouillon
·
Published
2010-02-21
·
Updated
2024-06-15
·
CVE-2010-0283
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
MIT Kerberos 5 versions 1.7 through 1.7.1
MIT Kerberos 5 version 1.8 alpha
mit-krb5 versions prior to 1.9.2-r1
Description
The issue allows remote attackers to cause problems with the system, including a denial of service, by sending invalid requests. Specifically, an invalid AS-REQ or TGS-REQ request can cause an assertion failure and daemon crash. The vulnerability may also lead to issues with confidentiality, integrity, and availability of protected information.
Recommendations
For MIT Kerberos 5 versions 1.7 through 1.7.1, update to version 1.7.2 or later.
For MIT Kerberos 5 version 1.8 alpha, update to a stable version.
For mit-krb5 versions prior to 1.9.2-r1, update to version 1.9.2-r1 or later.
As a temporary workaround, consider restricting access to the KDC to minimize the risk of exploitation.
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mit Kerberos 5
Mit-Krb5