CVE-2003-0060 — Use of Externally-Controlled Format String in Kerberos 5
5 documents5 sources
Severity
7.5HIGHNVD
EPSS
9.1%
top 7.31%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedFeb 19
Latest updateApr 29
Description
Format string vulnerabilities in the logging routines for MIT Kerberos V5 Key Distribution Center (KDC) before 1.2.5 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via format string specifiers in Kerberos principal names.
CVSS vector
AV:N/AC:L/C:P/I:P/A:PExploitability: 10.0 | Impact: 6.4
Affected Packages2 packages
Patches
🔴Vulnerability Details
3GHSA▶
GHSA-63v6-h3h2-rxp5: Format string vulnerabilities in the logging routines for MIT Kerberos V5 Key Distribution Center (KDC) before 1↗2022-04-29
OSV▶
CVE-2003-0060: Format string vulnerabilities in the logging routines for MIT Kerberos V5 Key Distribution Center (KDC) before 1↗2003-02-19
CVEList▶
CVE-2003-0060: Format string vulnerabilities in the logging routines for MIT Kerberos V5 Key Distribution Center (KDC) before 1↗2003-02-01
📋Vendor Advisories
1Debian▶
CVE-2003-0060: krb5 - Format string vulnerabilities in the logging routines for MIT Kerberos V5 Key Di...↗2003