CVE-2010-1324
Published Dec 2, 2010
Last updated 5 years ago
Overview
- Description
- MIT Kerberos 5 (aka krb5) 1.7.x and 1.8.x through 1.8.3 does not properly determine the acceptability of checksums, which might allow remote attackers to forge GSS tokens, gain privileges, or have unspecified other impact via (1) an unkeyed checksum, (2) an unkeyed PAC checksum, or (3) a KrbFastArmoredReq checksum based on an RC4 key.
- Source
- cve@mitre.org
- NVD status
- Modified
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 3.0
- Type
- Primary
- Base score
- 3.7
- Impact score
- 1.4
- Exploitability score
- 2.2
- Vector string
- CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
- Severity
- LOW
CVSS 2.0
- Type
- Primary
- Base score
- 4.3
- Impact score
- 2.9
- Exploitability score
- 8.6
- Vector string
- AV:N/AC:M/Au:N/C:N/I:P/A:N
Weaknesses
- nvd@nist.gov
- CWE-310
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:mit:kerberos_5:1.7:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "DFB1190E-BE7A-4C6B-862D-D5747C64E980" }, { "criteria": "cpe:2.3:a:mit:kerberos_5:1.7.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "4B09C090-B842-43C7-B8A6-DBF63D80FEC3" }, { "criteria": "cpe:2.3:a:mit:kerberos_5:1.8:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "36823B2B-5C72-4FF3-9301-FB263EB8CE09" }, { "criteria": "cpe:2.3:a:mit:kerberos_5:1.8.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "59AFA33E-FEBC-45F5-9EC6-8AA363163FB5" }, { "criteria": "cpe:2.3:a:mit:kerberos_5:1.8.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "04D83332-B2FD-4E86-A76C-C3F1CD3B3A31" }, { "criteria": "cpe:2.3:a:mit:kerberos_5:1.8.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "758A0011-20ED-414A-9DF3-50A161DF8BC2" } ], "operator": "OR" } ] } ]