CVE-2001-0034: High severity KTH KTH Kerberos vulnerability
Published Feb 16, 2001
·Updated
KTH Kerberos IV allows local users to specify an alternate proxy using the krb4proxy variable, which allows the user to generate false proxy responses and possibly gain privileges.
Affected Software
1 affected component
KTH KTH Kerberos<=4.1.0.3
Remediation
Event History
Feb 16, 2001
CVE Published
05:00 AM
May 7, 2001
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2001-0034?
CVE-2001-0034 is considered to have a medium severity due to the potential for privilege escalation.
2
How do I fix CVE-2001-0034?
To fix CVE-2001-0034, it is recommended to upgrade to a version of KTH Kerberos later than 4.1.0.3.
3
What vulnerabilities does CVE-2001-0034 expose?
CVE-2001-0034 exposes a vulnerability that allows local users to generate false proxy responses.
4
Who is affected by CVE-2001-0034?
CVE-2001-0034 affects installations of KTH Kerberos versions up to and including 4.1.0.3.
5
Can CVE-2001-0034 be exploited remotely?
No, CVE-2001-0034 is specifically a local privilege escalation vulnerability.