Vulnerability Name:
CVE-2003-0058 (CCN-10099)
Assigned:
2002-09-16
Published:
2002-09-16
Updated:
2020-01-21
Summary:
MIT Kerberos V5 Key Distribution Center (KDC) before 1.2.5 allows remote authenticated attackers to cause a denial of service (crash) on KDCs within the same realm via a certain protocol request that causes a null dereference.
CVSS v3 Severity:
3.5 Low
(CCN CVSS v3.1 Vector:
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L
)
Exploitability Metrics:
Attack Vector (AV):
Network
Attack Complexity (AC):
Low
Privileges Required (PR):
Low
User Interaction (UI):
Required
Scope:
Scope (S):
Unchanged
Impact Metrics:
Confidentiality (C):
None
Integrity (I):
None
Availibility (A):
Low
CVSS v2 Severity:
5.0 Medium
(CVSS v2 Vector:
AV:N/AC:L/Au:N/C:N/I:N/A:P
)
3.7 Low
(Temporal CVSS v2 Vector:
AV:N/AC:L/Au:N/C:N/I:N/A:P/E:U/RL:OF/RC:C
)
Exploitability Metrics:
Access Vector (AV):
Network
Access Complexity (AC):
Low
Authentication (Au):
None
Impact Metrics:
Confidentiality (C):
None
Integrity (I):
None
Availibility (A):
Partial
4.0 Medium
(CCN CVSS v2 Vector:
AV:N/AC:L/Au:S/C:N/I:N/A:P
)
3.0 Low
(CCN Temporal CVSS v2 Vector:
AV:N/AC:L/Au:S/C:N/I:N/A:P/E:U/RL:OF/RC:C
)
Exploitability Metrics:
Access Vector (AV):
Network
Access Complexity (AC):
Low
Athentication (Au):
Single_Instance
Impact Metrics:
Confidentiality (C):
None
Integrity (I):
None
Availibility (A):
Partial
Vulnerability Type:
CWE-Other
Vulnerability Consequences:
Denial of Service
References:
Source: MITRE
Type: CNA
CVE-2003-0058
Source: CONECTIVA
Type: UNKNOWN
CLSA-2003:639
Source: CCN
Type: Conectiva Linux Security Announcement CLSA-2003:639
krb5
Source: CCN
Type: RHSA-2003-051
Updated kerberos packages fix various vulnerabilities
Source: CCN
Type: RHSA-2003-052
krb5 security update
Source: CCN
Type: RHSA-2003-168
Updated kerberos packages fix various vulnerabilities
Source: CCN
Type: Sun Alert ID: 50142
Several Kerberos Applications are Vulnerable to a Denial of Service (DoS)
Source: SUNALERT
Type: UNKNOWN
50142
Source: CCN
Type: MIT Kerberos Web site
Kerberos: The Network Authentication Protocol
Source: CCN
Type: MIT krb5 Security Advisory 2003-001
Multiple vulnerabilities in old releases of MIT Kerberos
Source: CONFIRM
Type: Patch, Vendor Advisory
http://web.mit.edu/kerberos/www/advisories/MITKRB5-SA-2003-001-multiple.txt
Source: CCN
Type: CIAC Information Bulletin N-037
Multiple Vulnerabilities in Old Releases of MIT Kerberos
Source: CCN
Type: US-CERT VU#661243
MIT Kerberos V5 KDC vulnerable to denial-of-service via null pointer dereference
Source: CERT-VN
Type: Patch, Third Party Advisory, US Government Resource
VU#661243
Source: MANDRAKE
Type: UNKNOWN
MDKSA-2003:043
Source: REDHAT
Type: UNKNOWN
RHSA-2003:051
Source: REDHAT
Type: UNKNOWN
RHSA-2003:052
Source: REDHAT
Type: UNKNOWN
RHSA-2003:168
Source: BID
Type: Patch, Vendor Advisory
6683
Source: CCN
Type: BID-6683
Kerberos Key Distribution Center Denial of Service Vulnerability
Source: XF
Type: UNKNOWN
kerberos-kdc-null-pointer-dos(10099)
Source: XF
Type: UNKNOWN
kerberos-kdc-null-pointer-dos(10099)
Source: OVAL
Type: UNKNOWN
oval:org.mitre.oval:def:1110
Vulnerable Configuration:
Configuration 1
:
cpe:/a:mit:kerberos_5:1.2.1:*:*:*:*:*:*:*
OR
cpe:/a:mit:kerberos_5:1.2.2:*:*:*:*:*:*:*
OR
cpe:/a:mit:kerberos_5:1.2.3:*:*:*:*:*:*:*
OR
cpe:/a:mit:kerberos_5:1.2.4:*:*:*:*:*:*:*
OR
cpe:/a:sun:enterprise_authentication_mechanism:1.0:*:*:*:*:*:*:*
Configuration 2
:
cpe:/o:sun:solaris:8.0:*:x86:*:*:*:*:*
OR
cpe:/o:sun:solaris:9.0:*:sparc:*:*:*:*:*
OR
cpe:/o:sun:sunos:5.8:*:*:*:*:*:*:*
Configuration CCN 1
:
cpe:/a:sun:seam:1.0:*:*:*:*:*:*:*
OR
cpe:/a:mit:kerberos_5:1.2.2:*:*:*:*:*:*:*
OR
cpe:/a:mit:kerberos_5:1.2.1:*:*:*:*:*:*:*
OR
cpe:/a:mit:kerberos_5:1.2.3:*:*:*:*:*:*:*
OR
cpe:/a:mit:kerberos_5:1.2.4:*:*:*:*:*:*:*
AND
cpe:/o:sun:sunos:5.6:*:*:*:*:*:*:*
OR
cpe:/o:sun:sunos:5.8:*:*:*:*:*:*:*
OR
cpe:/o:redhat:linux:6.2:*:*:*:*:*:*:*
OR
cpe:/o:redhat:linux:7:*:*:*:*:*:*:*
OR
cpe:/o:redhat:linux:7.1:*:*:*:*:*:*:*
OR
cpe:/o:redhat:linux:7.2:*:*:*:*:*:*:*
OR
cpe:/o:mandrakesoft:mandrake_linux:8.2:*:*:*:*:*:*:*
OR
cpe:/o:conectiva:linux:8.0:*:*:*:*:*:*:*
OR
cpe:/o:redhat:linux:7.3:*:*:*:*:*:*:*
OR
cpe:/o:sun:sunos:5.9:*:*:*:*:*:*:*
OR
cpe:/o:redhat:linux:8.0:*:*:*:*:*:*:*
OR
cpe:/o:mandrakesoft:mandrake_linux:9.0:*:*:*:*:*:*:*
OR
cpe:/a:mandrakesoft:mandrake_multi_network_firewall:8.2:*:*:*:*:*:*:*
OR
cpe:/o:mandrakesoft:mandrake_linux_corporate_server:2.1:*:*:*:*:*:*:*
OR
cpe:/o:mandrakesoft:mandrake_linux:9.1:*:*:*:*:*:*:*
OR
cpe:/o:redhat:enterprise_linux:2.1:*:as:*:*:*:*:*
OR
cpe:/o:redhat:enterprise_linux:2.1:*:es:*:*:*:*:*
OR
cpe:/o:redhat:enterprise_linux:2.1:*:ws:*:*:*:*:*
OR
cpe:/o:sun:sunos:5.7:*:*:*:*:*:*:*
OR
cpe:/o:redhat:linux_advanced_workstation:2.1:*:itanium:*:*:*:*:*
OR
cpe:/o:redhat:linux:7.1:*:*:*:*:*:pseries:*
OR
cpe:/o:redhat:linux:7.1:*:*:*:*:*:iseries:*
OR
cpe:/o:mandrakesoft:mandrake_linux:8.2:*:ppc:*:*:*:*:*
OR
cpe:/o:mandrakesoft:mandrake_linux:9.1:*:ppc:*:*:*:*:*
OR
cpe:/o:mandrakesoft:mandrake_linux_corporate_server:2.1:*:x86_64:*:*:*:*:*
Denotes that component is vulnerable
Oval Definitions
Definition ID
Class
Title
Last Modified
oval:org.mitre.oval:def:1110
V
Kerberos V5 Null Pointer DoS Vulnerability
2005-03-09
BACK
mit
kerberos 5 1.2.1
mit
kerberos 5 1.2.2
mit
kerberos 5 1.2.3
mit
kerberos 5 1.2.4
sun
enterprise authentication mechanism 1.0
sun
solaris 8.0
sun
solaris 9.0
sun
sunos 5.8
sun
seam 1.0
mit
kerberos 5 1.2.2
mit
kerberos 5 1.2.1
mit
kerberos 5 1.2.3
mit
kerberos 5 1.2.4
sun
solaris 2.6
sun
solaris 8
redhat
linux 6.2
redhat
linux 7
redhat
linux 7.1
redhat
linux 7.2
mandrakesoft
mandrake linux 8.2
conectiva
linux 8.0
redhat
linux 7.3
sun
solaris 9
redhat
linux 8.0
mandrakesoft
mandrake linux 9.0
mandrakesoft
mandrake multi network firewall 8.2
mandrakesoft
mandrake linux corporate server 2.1
mandrakesoft
mandrake linux 9.1
redhat
enterprise linux 2.1
redhat
enterprise linux 2.1
redhat
enterprise linux 2.1
sun
solaris 7.0
redhat
linux advanced workstation 2.1
redhat
linux 7.1
redhat
linux 7.1
mandrakesoft
mandrake linux 8.2
mandrakesoft
mandrake linux 9.1
mandrakesoft
mandrake linux corporate server 2.1