CVE-2003-0059Kerberos 5 vulnerability

7 documents7 sources
Severity
7.5HIGHNVD
EPSS
3.2%
top 12.93%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedFeb 19
Latest updateApr 29

Description

Unknown vulnerability in the chk_trans.c of the libkrb5 library for MIT Kerberos V5 before 1.2.5 allows users from one realm to impersonate users in other realms that have the same inter-realm keys.

CVSS vector

AV:N/AC:L/C:P/I:P/A:PExploitability: 10.0 | Impact: 6.4

Affected Packages2 packages

NVDmit/kerberos_51.2.1, 1.2.2+1
Debianmit/krb5< 1.2.5-1+3

Patches

🔴Vulnerability Details

3
GHSA
GHSA-p9j8-4q5m-jqv4: Unknown vulnerability in the chk_trans2022-04-29
CVEList
CVE-2003-0059: Unknown vulnerability in the chk_trans2004-09-01
OSV
CVE-2003-0059: Unknown vulnerability in the chk_trans2003-02-19

📋Vendor Advisories

2
Red Hat
security flaw2003-01-28
Debian
CVE-2003-0059: krb5 - Unknown vulnerability in the chk_trans.c of the libkrb5 library for MIT Kerberos...2003

💬Community

1
Bugzilla
CVE-2003-0059 security flaw2018-08-16
CVE-2003-0059 — MIT Kerberos 5 vulnerability | cvebase