CVE Vulnerabilities

CVE-2014-5351

Published: Oct 10, 2014 | Modified: Nov 21, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
2.1 LOW
AV:N/AC:H/Au:S/C:P/I:N/A:N
RedHat/V2
2.1 MODERATE
AV:N/AC:H/Au:S/C:P/I:N/A:N
RedHat/V3
Ubuntu
LOW

The kadm5_randkey_principal_3 function in lib/kadm5/srv/svr_principal.c in kadmind in MIT Kerberos 5 (aka krb5) before 1.13 sends old keys in a response to a -randkey -keepold request, which allows remote authenticated users to forge tickets by leveraging administrative access.

Affected Software

Name Vendor Start Version End Version
Kerberos_5 Mit 1.12.2 (including) 1.12.2 (including)
Krb5 Ubuntu lucid *
Krb5 Ubuntu precise *
Krb5 Ubuntu trusty *
Krb5 Ubuntu upstream *

References