CVE-2003-0060Use of Externally-Controlled Format String in Kerberos 5

5 documents5 sources
Severity
7.5HIGHNVD
EPSS
9.1%
top 7.31%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedFeb 19
Latest updateApr 29

Description

Format string vulnerabilities in the logging routines for MIT Kerberos V5 Key Distribution Center (KDC) before 1.2.5 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via format string specifiers in Kerberos principal names.

CVSS vector

AV:N/AC:L/C:P/I:P/A:PExploitability: 10.0 | Impact: 6.4

Affected Packages2 packages

NVDmit/kerberos_54 versions+3
Debianmit/krb5< 1.2.4+3

Patches

🔴Vulnerability Details

3
GHSA
GHSA-63v6-h3h2-rxp5: Format string vulnerabilities in the logging routines for MIT Kerberos V5 Key Distribution Center (KDC) before 12022-04-29
OSV
CVE-2003-0060: Format string vulnerabilities in the logging routines for MIT Kerberos V5 Key Distribution Center (KDC) before 12003-02-19
CVEList
CVE-2003-0060: Format string vulnerabilities in the logging routines for MIT Kerberos V5 Key Distribution Center (KDC) before 12003-02-01

📋Vendor Advisories

1
Debian
CVE-2003-0060: krb5 - Format string vulnerabilities in the logging routines for MIT Kerberos V5 Key Di...2003
CVE-2003-0060 — MIT Kerberos 5 vulnerability | cvebase