CVE-2010-1324
Summary
| CVE | CVE-2010-1324 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2010-12-02 16:22:20 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | MIT Kerberos 5 (aka krb5) 1.7.x and 1.8.x through 1.8.3 does not properly determine the acceptability of checksums, which might allow remote attackers to forge GSS tokens, gain privileges, or have unspecified other impact via (1) an unkeyed checksum, (2) an unkeyed PAC checksum, or (3) a KrbFastArmoredReq checksum based on an RC4 key. |
Risk And Classification
Primary CVSS: v3.0 3.7 LOW from [email protected]
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
Problem Types: CWE-310 | n/a
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.0 | [email protected] | Primary | 3.7 | LOW | CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N |
| 2.0 | [email protected] | Primary | 4.3 | AV:N/AC:M/Au:N/C:N/I:P/A:N |
CVSS v3.0 Breakdown
Attack Vector
NetworkAttack Complexity
HighPrivileges Required
NoneUser Interaction
NoneScope
UnchangedConfidentiality
NoneIntegrity
LowAvailability
NoneCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
NoneIntegrity
PartialAvailability
NoneAV:N/AC:M/Au:N/C:N/I:P/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Mit | Kerberos 5 | 1.7 | All | All | All |
| Application | Mit | Kerberos 5 | 1.7.1 | All | All | All |
| Application | Mit | Kerberos 5 | 1.8 | All | All | All |
| Application | Mit | Kerberos 5 | 1.8.1 | All | All | All |
| Application | Mit | Kerberos 5 | 1.8.2 | All | All | All |
| Application | Mit | Kerberos 5 | 1.8.3 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| [SECURITY] Fedora 14 Update: krb5-1.8.2-7.fc14 | af854a3a-2127-422b-91ae-364da2661108 | lists.fedoraproject.org | |
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| VMSA-2011-0007 | af854a3a-2127-422b-91ae-364da2661108 | www.vmware.com | |
| '[security bulletin] HPSBUX02623 SSRT100355 rev.1 - HP-UX Running Kerberos, Remote Unauthorized Modif' - MARC | af854a3a-2127-422b-91ae-364da2661108 | marc.info | |
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| web.mit.edu/kerberos/advisories/MITKRB5-SA-2010-007.txt | af854a3a-2127-422b-91ae-364da2661108 | web.mit.edu | Vendor Advisory |
| HP-UX update for Kerberos - Advisories - Community | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Red Hat update for krb5 - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| osvdb.org/69609 | af854a3a-2127-422b-91ae-364da2661108 | osvdb.org | |
| APPLE-SA-2011-03-21-1 Mac OS X v10.6.7 and Security Update 2011-001 | af854a3a-2127-422b-91ae-364da2661108 | lists.apple.com | |
| Oracle Critical Patch Update - July 2015 | af854a3a-2127-422b-91ae-364da2661108 | www.oracle.com | Patch, Vendor Advisory |
| VMware KB: VMware ESXi 4.1 Patch ESXi410-201104401-SG: Updates Firmware | af854a3a-2127-422b-91ae-364da2661108 | kb.vmware.com | |
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | |
| MIT Kerberos 5 1.7.x Checksum Multiple Remote Security Bypass Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| [SECURITY] Fedora 13 Update: krb5-1.7.1-16.fc13 | af854a3a-2127-422b-91ae-364da2661108 | lists.fedoraproject.org | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| Support / Security / Advisories / / MDVSA-2010:246 | Mandriva | af854a3a-2127-422b-91ae-364da2661108 | www.mandriva.com | |
| MIT Kerberos Checksum Handling Errors May Let Remote or Remote Authenticated Users Forge/Modify Certain Data - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| [security-announce] SUSE Security Summary Report: SUSE-SR:2010:023 | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| USN-1030-1: Kerberos vulnerabilities | Ubuntu | af854a3a-2127-422b-91ae-364da2661108 | www.ubuntu.com | |
| About the security content of Mac OS X v10.6.7 and Security Update 2011-001 | af854a3a-2127-422b-91ae-364da2661108 | support.apple.com | |
| [security-announce] SUSE Security Summary Report: SUSE-SR:2010:024 | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| Support | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | |
| [Security-announce] VMSA-2011-0007 VMware ESXi and ESX Denial of Service and third party updates for Likewise components and ESX Service Console | af854a3a-2127-422b-91ae-364da2661108 | lists.vmware.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.