VDB

DEBIAN-CVE-2010-4021

DEBIAN-CVE-2010-4021 PUBLISHED

The Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.7 does not properly restrict the use of TGT credentials for armoring TGS requests, which might allow remote authenticated users to impersonate a client by rewriting an inner request, aka a "KrbFastReq forgery issue."

Affected Products

VendorProductVersions
Debian:13krb50, 0, 0
Debian:12krb50, 0, 0
Debian:14krb50, 0, 0
Debian:11krb50, 0, 0

Timeline

  • Dec 2, 2010 CVE Published
  • Apr 28, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›