PT-2010-1102 · Mit · Mit Kerberos 5

Published

2010-12-02

·

Updated

2024-06-15

·

CVE-2010-4021

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions MIT Kerberos 5 versions 1.7 through 1.9.2-r1
Description The Key Distribution Center (KDC) in MIT Kerberos 5 does not properly restrict the use of TGT credentials for armoring TGS requests, which might allow remote authenticated users to impersonate a client by rewriting an inner request. Multiple vulnerabilities in the mit-krb5 package can lead to breaches of confidentiality, integrity, and availability of protected information, and can be exploited remotely.
Recommendations For versions 1.7 through 1.9.2-r1, update to a version later than 1.9.2-r1 to resolve the issue. At the moment, there is no information about other specific fixes for this vulnerability.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-09426
CVE-2010-4021
OPENSUSE-SU-2024:10004-1

Affected Products

Mit Kerberos 5