CVE Vulnerabilities

CVE-2010-1324

Published: Dec 02, 2010 | Modified: Apr 11, 2025
CVSS 3.x
3.7
LOW
Source:
NVD
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
RedHat/V2
4.3 IMPORTANT
AV:N/AC:M/Au:N/C:N/I:P/A:N
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

MIT Kerberos 5 (aka krb5) 1.7.x and 1.8.x through 1.8.3 does not properly determine the acceptability of checksums, which might allow remote attackers to forge GSS tokens, gain privileges, or have unspecified other impact via (1) an unkeyed checksum, (2) an unkeyed PAC checksum, or (3) a KrbFastArmoredReq checksum based on an RC4 key.

Affected Software

NameVendorStart VersionEnd Version
Kerberos_5Mit1.7 (including)1.7 (including)
Kerberos_5Mit1.7.1 (including)1.7.1 (including)
Kerberos_5Mit1.8 (including)1.8 (including)
Kerberos_5Mit1.8.1 (including)1.8.1 (including)
Kerberos_5Mit1.8.2 (including)1.8.2 (including)
Kerberos_5Mit1.8.3 (including)1.8.3 (including)
Red Hat Enterprise Linux 6RedHatkrb5-0:1.8.2-3.el6_0.3*
Krb5Ubuntukarmic*
Krb5Ubuntulucid*
Krb5Ubuntumaverick*

References