|
|
Log in / Subscribe / Register

kerberos - cryptographic weakness

Package(s):kerberos, heimdal, openafs CVE #(s):CAN-2003-0138 CAN-2003-0139
Created:March 26, 2003 Updated:May 27, 2003
Description: Version 4 of the Kerberos protocol contains a cryptographic weakness which enables a chosen-plaintext attack. A suitably equipped attacker can impersonate any principal in the realm. Another weakness allows the creation of false Kerberos tickets. Given the weaknesses in the cryptography, cross-realm authentication cannot be performed in a secure way.

OpenAFS kaserver implements version 4 of the Kerberos protocol, and therefore is also vulnerable.

Alerts:
Gentoo 200305-09 heimdal 2003-05-27
Debian DSA-269-2 heimdal 2003-04-09
Immunix IMNX-2003-7+-007-01 Kerberos 5 2003-04-07
Red Hat RHSA-2003:091-01 krb5 2003-04-02
Mandrake MDKSA-2003:043 krb5 2003-04-01
Gentoo 200303-28 krb5 2003-03-31
Gentoo 200303-26 openafs 2003-03-30
Debian DSA-273-1 krb4 2003-03-28
Red Hat RHSA-2003:051-01 krb5 2003-03-26
Debian DSA-269-1 heimdal 2003-03-26

to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds