First published: Fri Feb 16 2001(Updated: )
KTH Kerberos IV allows local users to specify an alternate proxy using the krb4_proxy variable, which allows the user to generate false proxy responses and possibly gain privileges.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
KTH Kerberos | <=4.1.0.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2001-0034 is considered to have a medium severity due to the potential for privilege escalation.
To fix CVE-2001-0034, it is recommended to upgrade to a version of KTH Kerberos later than 4.1.0.3.
CVE-2001-0034 exposes a vulnerability that allows local users to generate false proxy responses.
CVE-2001-0034 affects installations of KTH Kerberos versions up to and including 4.1.0.3.
No, CVE-2001-0034 is specifically a local privilege escalation vulnerability.