PT-2010-1099 · Mit+2 · Mit Kerberos 5+2

Published

2010-11-30

·

Updated

2024-06-15

·

CVE-2010-1323

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions MIT Kerberos 5 (aka krb5) versions 1.3.x through 1.8.3 MIT Kerberos 5 (aka krb5) versions prior to 1.9.2
Description The issue is related to the improper determination of checksum acceptability, which could allow remote attackers to modify user-visible prompt text, modify a response to a Key Distribution Center (KDC), or forge a KRB-SAFE message via certain checksums. These checksums might be unkeyed or use RC4 keys. The vulnerability can be exploited remotely and may lead to a breach of confidentiality, integrity, and availability of protected information.
Recommendations For versions 1.3.x through 1.8.3, update to a version newer than 1.8.3. For versions prior to 1.9.2, update to version 1.9.2 or newer. As a temporary workaround, consider restricting the use of unkeyed or RC4-keyed checksums until a patch is available.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-09426
CVE-2010-1323
DSA-2129-1
HPSBUX02623
OPENSUSE-SU-2024:10004-1
RHSA-2010:0925
RHSA-2010:0926
RHSA-2010_0925
RHSA-2010_0926

Affected Products

Hp-Ux
Mit Kerberos 5
Red Hat