VDB
CVE-2003-0139
CVE-2003-0139
PUBLISHED
Reported by mitre · Published March 21, 2003
Certain weaknesses in the implementation of version 4 of the Kerberos protocol (krb4) in the krb5 distribution, when triple-DES keys are used to key krb4 services, allow an attacker to create krb4 tickets for unauthorized principals using a cut-and-paste attack and "ticket splicing."
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | n/a |
| n/a | n/a | n/a, n/a, n/a |
Timeline
- Mar 21, 2003 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 20, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 26, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 3, 2023 EPSS Score
- Jul 17, 2023 EPSS Score
- Sep 8, 2023 EPSS Score
References
- RHSA-2003:052 vendor-advisoryx_refsource_REDHAT
- 20030331 GLSA: krb5 & mit-krb5 (200303-28) mailing-listx_refsource_BUGTRAQ
- VU#442569 third-party-advisoryx_refsource_CERT-VN
- x_refsource_CONFIRM
- RHSA-2003:091 vendor-advisoryx_refsource_REDHAT
- DSA-273 vendor-advisoryx_refsource_DEBIAN
- oval:org.mitre.oval:def:250 vdb-entrysignaturex_refsource_OVAL
- RHSA-2003:051 vendor-advisoryx_refsource_REDHAT
- 20030319 MITKRB5-SA-2003-004: Cryptographic weaknesses in Kerberos v4 mailing-listx_refsource_BUGTRAQ
- DSA-266 vendor-advisoryx_refsource_DEBIAN
- 20030330 GLSA: openafs (200303-26) mailing-listx_refsource_BUGTRAQ