| Vulnerability Name: | CVE-2003-0139 (CCN-11570) | ||||||||||||||||
| Assigned: | 2003-03-17 | ||||||||||||||||
| Published: | 2003-03-17 | ||||||||||||||||
| Updated: | 2018-10-19 | ||||||||||||||||
| Summary: | Certain weaknesses in the implementation of version 4 of the Kerberos protocol (krb4) in the krb5 distribution, when triple-DES keys are used to key krb4 services, allow an attacker to create krb4 tickets for unauthorized principals using a cut-and-paste attack and "ticket splicing." | ||||||||||||||||
| CVSS v3 Severity: | 7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||||||||||
| CVSS v2 Severity: | 7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
| ||||||||||||||||
| Vulnerability Type: | CWE-Other | ||||||||||||||||
| Vulnerability Consequences: | Bypass Security | ||||||||||||||||
| References: | Source: MITRE Type: CNA CVE-2003-0139 Source: CCN Type: Conectiva Linux Security Announcement CLSA-2003:639 krb5 Source: BUGTRAQ Type: UNKNOWN 20030319 MITKRB5-SA-2003-004: Cryptographic weaknesses in Kerberos v4 Source: CCN Type: RHSA-2003-051 Updated kerberos packages fix various vulnerabilities Source: CCN Type: RHSA-2003-052 krb5 security update Source: CCN Type: RHSA-2003-091 Updated kerberos packages fix various vulnerabilities Source: CCN Type: MIT krb5 Security Advisory 2003-004 Cryptographic weaknesses in Kerberos v4 protocol Source: CONFIRM Type: Patch, Vendor Advisory http://web.mit.edu/kerberos/www/advisories/MITKRB5-SA-2003-004-krb4.txt Source: CCN Type: MIT krb5 Release 1.2 Web site Kerberos 5 Release 1.2 Source: CCN Type: CIAC Information Bulletin N-057 Cryptographic weaknesses in Kerberos v4 protocol Source: DEBIAN Type: UNKNOWN DSA-266 Source: DEBIAN Type: UNKNOWN DSA-273 Source: DEBIAN Type: DSA-266 krb5 -- several vulnerabilities Source: DEBIAN Type: DSA-273 krb4 -- Cryptographic weakness Source: CCN Type: US-CERT VU#442569 MIT Kerberos vulnerable to ticket splicing when using Kerberos4 triple DES service tickets Source: CERT-VN Type: Patch, Third Party Advisory, US Government Resource VU#442569 Source: CCN Type: Gentoo Linux Security Announcement 200303-28 krb5 & mit-krb5 multiple vulnerabilities fixed Source: CCN Type: Immunix OS Security Advisory IMNX-2003-7+-007-01 Kerberos 5 Source: CCN Type: Gentoo Linux Security Announcement 200305-09 heimdal protocol bug in the kerberos v4 cross-realm operation Source: REDHAT Type: UNKNOWN RHSA-2003:051 Source: REDHAT Type: UNKNOWN RHSA-2003:052 Source: REDHAT Type: UNKNOWN RHSA-2003:091 Source: BUGTRAQ Type: UNKNOWN 20030331 GLSA: krb5 & mit-krb5 (200303-28) Source: BUGTRAQ Type: UNKNOWN 20030330 GLSA: openafs (200303-26) Source: CCN Type: BID-7113 Multiple Cryptographic Weaknesses in Kerberos 4 Protocol Source: CCN Type: TLSA-2003-29 Multiple vulnerabilities in krb5 Source: XF Type: UNKNOWN kerberos-protocol-create-tickets(11570) Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:250 | ||||||||||||||||
| Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||||||
| Oval Definitions | |||||||||||||||||
| |||||||||||||||||
| BACK | |||||||||||||||||