[Forgot Password]
Login  Register Subscribe

30480

 
 

423868

 
 

252097

 
 

909

 
 

196747

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2010-1324Date: (C)2010-12-02   (M)2024-02-22


MIT Kerberos 5 (aka krb5) 1.7.x and 1.8.x through 1.8.3 does not properly determine the acceptability of checksums, which might allow remote attackers to forge GSS tokens, gain privileges, or have unspecified other impact via (1) an unkeyed checksum, (2) an unkeyed PAC checksum, or (3) a KrbFastArmoredReq checksum based on an RC4 key.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V3 Severity:CVSS V2 Severity:
CVSS Score : 3.7CVSS Score : 4.3
Exploit Score: 2.2Exploit Score: 8.6
Impact Score: 1.4Impact Score: 2.9
 
CVSS V3 Metrics:CVSS V2 Metrics:
Attack Vector: NETWORKAccess Vector: NETWORK
Attack Complexity: HIGHAccess Complexity: MEDIUM
Privileges Required: NONEAuthentication: NONE
User Interaction: NONEConfidentiality: NONE
Scope: UNCHANGEDIntegrity: PARTIAL
Confidentiality: NONEAvailability: NONE
Integrity: LOW 
Availability: NONE 
  
Reference:
SECTRACK-1024803
http://www.securityfocus.com/archive/1/514953/100/0/threaded
http://www.securityfocus.com/archive/1/517739/100/0/threaded
SECUNIA-42399
SECUNIA-43015
BID-45116
OSVDB-69609
ADV-2010-3094
ADV-2010-3095
ADV-2010-3118
ADV-2011-0187
APPLE-SA-2011-03-21-1
FEDORA-2010-18409
FEDORA-2010-18425
HPSBUX02623
MDVSA-2010:246
RHSA-2010:0925
SUSE-SR:2010:023
SUSE-SR:2010:024
USN-1030-1
http://lists.vmware.com/pipermail/security-announce/2011/000133.html
http://kb.vmware.com/kb/1035108
http://support.apple.com/kb/HT4581
http://web.mit.edu/kerberos/advisories/MITKRB5-SA-2010-007.txt
http://www.oracle.com/technetwork/topics/security/cpujul2015-2367936.html
http://www.vmware.com/security/advisories/VMSA-2011-0007.html
oval:org.mitre.oval:def:11936

CWE    1
CWE-310
OVAL    14
oval:org.secpod.oval:def:101237
oval:org.secpod.oval:def:101239
oval:org.secpod.oval:def:1503335
oval:org.secpod.oval:def:700200
...

© SecPod Technologies