PT-2012-3015 · Mit · Mit Kerberos 5

Vincent Danen

·

Published

2012-06-07

·

Updated

2024-06-15

·

CVE-2012-1012

CVSS v2.0

5.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions MIT Kerberos 5 (krb5) versions 1.10 through 1.10.0
Description The issue is related to the kadmin protocol implementation in MIT Kerberos 5, where the server/server stubs.c file does not properly restrict access to certain operations. This might allow remote authenticated administrators to modify or read string attributes by leveraging the global list privilege. The operations in question are SET STRING and GET STRINGS.
Recommendations For MIT Kerberos 5 versions 1.10 through 1.10.0, update to version 1.10.1 or later to resolve the issue.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2012-1012
OPENSUSE-SU-2024:10004-1

Affected Products

Mit Kerberos 5