CVE-2003-0139
Certain weaknesses in the implementation of version 4 of the Kerberos protocol (krb4) in the krb5 distribution, when triple-DES keys are used to key krb4 services, allow an attacker to create krb4 tickets for unauthorized principals using a…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (4.28%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Certain weaknesses in the implementation of version 4 of the Kerberos protocol (krb4) in the krb5 distribution, when triple-DES keys are used to key krb4 services, allow an attacker to create krb4 tickets for unauthorized principals using a cut-and-paste attack and "ticket splicing."
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 4.28% probability · 91th percentile
- CISA KEV
- Not listed
- Affected
- mit/kerberos
- Source
- cve@mitre.org
References
- http://marc.info/?l=bugtraq&m=104791775804776&w=2
- http://web.mit.edu/kerberos/www/advisories/MITKRB5-SA-2003-004-krb4.txtPatch, Vendor Advisory
- http://www.debian.org/security/2003/dsa-266
- http://www.debian.org/security/2003/dsa-273
- http://www.kb.cert.org/vuls/id/442569Patch, Third Party Advisory, US Government Resource
- http://www.redhat.com/support/errata/RHSA-2003-051.html
- http://www.redhat.com/support/errata/RHSA-2003-052.html
- http://www.redhat.com/support/errata/RHSA-2003-091.html
- http://www.securityfocus.com/archive/1/316960/30/25250/threaded
- http://www.securityfocus.com/archive/1/317130/30/25250/threaded
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A250
- http://marc.info/?l=bugtraq&m=104791775804776&w=2
- http://web.mit.edu/kerberos/www/advisories/MITKRB5-SA-2003-004-krb4.txtPatch, Vendor Advisory
- http://www.debian.org/security/2003/dsa-266
- http://www.debian.org/security/2003/dsa-273
- http://www.kb.cert.org/vuls/id/442569Patch, Third Party Advisory, US Government Resource
- http://www.redhat.com/support/errata/RHSA-2003-051.html
- http://www.redhat.com/support/errata/RHSA-2003-052.html
- http://www.redhat.com/support/errata/RHSA-2003-091.html
- http://www.securityfocus.com/archive/1/316960/30/25250/threaded
- http://www.securityfocus.com/archive/1/317130/30/25250/threaded
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A250
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.