CVE-2004-0371
published 2004-05-04CVE-2004-0371: Heimdal 0.6.x before 0.6.1 and 0.5.x before 0.5.3 does not properly perform certain consistency checks for cross-realm requests, which allows remote attackers…
PriorityP419medium5CVSS 2.0
AVNACLAuNCNIPAN
EPSS
1.53%
72.0th percentile
Heimdal 0.6.x before 0.6.1 and 0.5.x before 0.5.3 does not properly perform certain consistency checks for cross-realm requests, which allows remote attackers with control of a realm to impersonate others in the cross-realm trust path.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | heimdal | < heimdal 0.6.1-1 (bookworm) | heimdal 0.6.1-1 (bookworm) |
| heimdal_project | heimdal | >= 0 < 0.6.1-1 | 0.6.1-1 |
| heimdal_project | heimdal | >= 0 < 0.6.1-1 | 0.6.1-1 |
| heimdal_project | heimdal | >= 0 < 0.6.1-1 | 0.6.1-1 |
| heimdal_project | heimdal | >= 0 < 0.6.1-1 | 0.6.1-1 |
| kth | heimdal | — | — |
| kth | heimdal | — | — |
| kth | heimdal | — | — |
| kth | heimdal | — | — |
| kth | heimdal | — | — |
| kth | heimdal | — | — |
| kth | heimdal | — | — |
| kth | heimdal | — | — |
| kth | heimdal | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
osv5.0MEDIUM
vendor_debian5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2004-0371: heimdal - Heimdal 0.6.x before 0.6.1 and 0.5.x before 0.5.3 does not properly perform cert...
vendor_debian·2004·CVSS 5.0
CVE-2004-0371 [MEDIUM] CVE-2004-0371: heimdal - Heimdal 0.6.x before 0.6.1 and 0.5.x before 0.5.3 does not properly perform cert...
Heimdal 0.6.x before 0.6.1 and 0.5.x before 0.5.3 does not properly perform certain consistency checks for cross-realm requests, which allows remote attackers with control of a realm to impersonate others in the cross-realm trust path.
Scope: local
bookworm: resolved (fixed in 0.6.1-1)
bullseye: resolved (fixed in 0.6.1-1)
forky: resolved (fixed in 0.6.1-1)
sid: resolved (fixed in 0.6.1-1)
trixie: resolved (fixed in 0.6.1-1)
GHSA
GHSA-p2xx-mp65-2vff: Heimdal 0
ghsa_unreviewed·2022-05-03
CVE-2004-0371 [MEDIUM] GHSA-p2xx-mp65-2vff: Heimdal 0
Heimdal 0.6.x before 0.6.1 and 0.5.x before 0.5.3 does not properly perform certain consistency checks for cross-realm requests, which allows remote attackers with control of a realm to impersonate others in the cross-realm trust path.
OSV
CVE-2004-0371: Heimdal 0
osv·2004-05-04·CVSS 5.0
CVE-2004-0371 [MEDIUM] CVE-2004-0371: Heimdal 0
Heimdal 0.6.x before 0.6.1 and 0.5.x before 0.5.3 does not properly perform certain consistency checks for cross-realm requests, which allows remote attackers with control of a realm to impersonate others in the cross-realm trust path.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-04:08.heimdal.ascftp://ftp.openbsd.org/pub/OpenBSD/patches/3.5/common/009_kerberos.patchhttp://security.gentoo.org/glsa/glsa-200404-09.xmlhttp://www.debian.org/security/2004/dsa-476http://www.pdc.kth.se/heimdal/advisory/2004-04-01/https://exchange.xforce.ibmcloud.com/vulnerabilities/15701ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-04:08.heimdal.ascftp://ftp.openbsd.org/pub/OpenBSD/patches/3.5/common/009_kerberos.patchhttp://security.gentoo.org/glsa/glsa-200404-09.xmlhttp://www.debian.org/security/2004/dsa-476http://www.pdc.kth.se/heimdal/advisory/2004-04-01/https://exchange.xforce.ibmcloud.com/vulnerabilities/15701
2004-05-04
Published