CVE-2003-0059: High severity MIT Kerberos 5 vulnerability
Published Feb 19, 2003
·Updated
Unknown vulnerability in the chktrans.c of the libkrb5 library for MIT Kerberos V5 before 1.2.5 allows users from one realm to impersonate users in other realms that have the same inter-realm keys.
Affected Software
2 affected components
MIT Kerberos 5=1.2.1
MIT Kerberos 5=1.2.2
Remediation
Patch Available
Patch Available
Event History
Feb 19, 2003
CVE Published
05:00 AM
Data Sourced
via NVD·05:00 AM
RemedyDescriptionSeverityAffected Software
Sep 1, 2004
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2003-0059?
CVE-2003-0059 is classified as a medium severity vulnerability due to its potential for user impersonation across realms.
2
How do I fix CVE-2003-0059?
To fix CVE-2003-0059, upgrade to MIT Kerberos V5 version 1.2.5 or later.
3
What systems are affected by CVE-2003-0059?
CVE-2003-0059 affects MIT Kerberos V5 versions 1.2.1 and 1.2.2.
4
What type of vulnerability is CVE-2003-0059?
CVE-2003-0059 is an impersonation vulnerability that allows user impersonation between realms.
5
Are there any known exploits for CVE-2003-0059?
There are no widely reported exploits specifically for CVE-2003-0059, but the vulnerability poses a significant risk.