Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2010-1323

Опубликовано: 02 дек. 2010
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 2.6
CVSS3: 3.7

Описание

MIT Kerberos 5 (aka krb5) 1.3.x, 1.4.x, 1.5.x, 1.6.x, 1.7.x, and 1.8.x through 1.8.3 does not properly determine the acceptability of checksums, which might allow remote attackers to modify user-visible prompt text, modify a response to a Key Distribution Center (KDC), or forge a KRB-SAFE message via certain checksums that (1) are unkeyed or (2) use RC4 keys.

РелизСтатусПримечание
dapper

released

1.4.3-5ubuntu0.12
devel

not-affected

1.8.3+dfsg-3
hardy

released

1.6.dfsg.3~beta1-2ubuntu1.6
karmic

released

1.7dfsg~beta3-1ubuntu0.7
lucid

released

1.8.1+dfsg-2ubuntu0.4
maverick

released

1.8.1+dfsg-5ubuntu0.2
upstream

needs-triage

Показывать по

EPSS

Процентиль: 88%
0.0417
Низкий

2.6 Low

CVSS2

3.7 Low

CVSS3

Связанные уязвимости

redhat
больше 14 лет назад

MIT Kerberos 5 (aka krb5) 1.3.x, 1.4.x, 1.5.x, 1.6.x, 1.7.x, and 1.8.x through 1.8.3 does not properly determine the acceptability of checksums, which might allow remote attackers to modify user-visible prompt text, modify a response to a Key Distribution Center (KDC), or forge a KRB-SAFE message via certain checksums that (1) are unkeyed or (2) use RC4 keys.

CVSS3: 3.7
nvd
больше 14 лет назад

MIT Kerberos 5 (aka krb5) 1.3.x, 1.4.x, 1.5.x, 1.6.x, 1.7.x, and 1.8.x through 1.8.3 does not properly determine the acceptability of checksums, which might allow remote attackers to modify user-visible prompt text, modify a response to a Key Distribution Center (KDC), or forge a KRB-SAFE message via certain checksums that (1) are unkeyed or (2) use RC4 keys.

CVSS3: 3.7
debian
больше 14 лет назад

MIT Kerberos 5 (aka krb5) 1.3.x, 1.4.x, 1.5.x, 1.6.x, 1.7.x, and 1.8.x ...

CVSS3: 3.7
github
около 3 лет назад

MIT Kerberos 5 (aka krb5) 1.3.x, 1.4.x, 1.5.x, 1.6.x, 1.7.x, and 1.8.x through 1.8.3 does not properly determine the acceptability of checksums, which might allow remote attackers to modify user-visible prompt text, modify a response to a Key Distribution Center (KDC), or forge a KRB-SAFE message via certain checksums that (1) are unkeyed or (2) use RC4 keys.

oracle-oval
больше 14 лет назад

ELSA-2010-0926: krb5 security update (MODERATE)

EPSS

Процентиль: 88%
0.0417
Низкий

2.6 Low

CVSS2

3.7 Low

CVSS3