CVE-2003-0138Kerberos vulnerability

7 documents7 sources
Severity
7.5HIGHNVD
EPSS
5.6%
top 9.63%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 24
Latest updateApr 29

Description

Version 4 of the Kerberos protocol (krb4), as used in Heimdal and other packages, allows an attacker to impersonate any principal in a realm via a chosen-plaintext attack.

CVSS vector

AV:N/AC:L/C:P/I:P/A:PExploitability: 10.0 | Impact: 6.4

Affected Packages3 packages

Debianheimdal_project/heimdal< 0.5.2-1+3
Debianmit/krb5< 1.2.7-3+3

Patches

🔴Vulnerability Details

3
GHSA
GHSA-qxpj-m267-3648: Version 4 of the Kerberos protocol (krb4), as used in Heimdal and other packages, allows an attacker to impersonate any principal in a realm via a cho2022-04-29
OSV
CVE-2003-0138: Version 4 of the Kerberos protocol (krb4), as used in Heimdal and other packages, allows an attacker to impersonate any principal in a realm via a cho2003-03-24
CVEList
CVE-2003-0138: Version 4 of the Kerberos protocol (krb4), as used in Heimdal and other packages, allows an attacker to impersonate any principal in a realm via a cho2003-03-21

📋Vendor Advisories

2
Red Hat
security flaw2003-03-19
Debian
CVE-2003-0138: heimdal - Version 4 of the Kerberos protocol (krb4), as used in Heimdal and other packages...2003

💬Community

1
Bugzilla
CVE-2003-0138 security flaw2018-08-16
CVE-2003-0138 — MIT Kerberos vulnerability | cvebase