CVE-2003-0058: Medium severity Sun Enterprise Authentication Mechanism vulnerability
Published Feb 19, 2003
·Updated
MIT Kerberos V5 Key Distribution Center (KDC) before 1.2.5 allows remote authenticated attackers to cause a denial of service (crash) on KDCs within the same realm via a certain protocol request that causes a null dereference.
Affected Software
8 affected components
Sun Enterprise Authentication Mechanism=1.0
mit Kerberos 5=1.2.1
mit Kerberos 5=1.2.2
mit Kerberos 5=1.2.3
mit Kerberos 5=1.2.4
Sun SunOS=5.8
Sun Solaris=9.0
Sun Solaris=8.0
Remediation
Patch Available
Patch Available
Event History
Feb 19, 2003
CVE Published
05:00 AM
Data Sourced
via NVD·05:00 AM
RemedyDescriptionSeverityAffected Software
Sep 1, 2004
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2003-0058?
CVE-2003-0058 is classified as a denial of service vulnerability.
2
How do I fix CVE-2003-0058?
To fix CVE-2003-0058, upgrade to MIT Kerberos V5 version 1.2.5 or later.
3
What software is affected by CVE-2003-0058?
CVE-2003-0058 affects MIT Kerberos 5 versions 1.2.1 to 1.2.4 and related Sun products.
4
What is the impact of exploiting CVE-2003-0058?
Exploiting CVE-2003-0058 can cause remote authenticated attackers to crash the Key Distribution Center.
5
When was CVE-2003-0058 disclosed?
CVE-2003-0058 was disclosed in January 2003.