CVE-2003-0060: High severity mit kerberos 5 vulnerability
Format string vulnerabilities in the logging routines for MIT Kerberos V5 Key Distribution Center (KDC) before 1.2.5 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via format string specifiers in Kerberos principal names.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2003-0060?
CVE-2003-0060 has a medium severity level due to the potential for remote denial of service and arbitrary code execution.
How do I fix CVE-2003-0060?
To address CVE-2003-0060, upgrade MIT Kerberos V5 to version 1.2.5 or later.
What are the affected versions for CVE-2003-0060?
CVE-2003-0060 affects MIT Kerberos versions 1.2.1, 1.2.2, 1.2.3, and 1.2.4.
Can CVE-2003-0060 be exploited remotely?
Yes, CVE-2003-0060 can be exploited remotely by attackers using specially crafted Kerberos principal names.
What impact does CVE-2003-0060 have on systems?
CVE-2003-0060 can cause a denial of service, resulting in crashes, and may allow for arbitrary code execution.