CVE-2003-0072: Medium severity MIT Kerberos vulnerability
The Key Distribution Center (KDC) in Kerberos 5 (krb5) 1.2.7 and earlier allows remote, authenticated attackers to cause a denial of service (crash) on KDCs within the same realm using a certain protocol request that causes an out-of-bounds read of an array (aka "array overrun").
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2003-0072?
CVE-2003-0072 is considered a denial of service vulnerability that can crash the Key Distribution Center (KDC) in Kerberos 5.
How do I fix CVE-2003-0072?
To fix CVE-2003-0072, you should upgrade to a patched version of MIT Kerberos 5 that addresses this vulnerability.
What versions are affected by CVE-2003-0072?
CVE-2003-0072 affects MIT Kerberos versions 1.2.7 and earlier, including several specific older versions like 1.0 and 1.1.
What type of attack does CVE-2003-0072 exploit?
CVE-2003-0072 can be exploited by remote, authenticated attackers to cause a denial of service through a specific protocol request.
Can CVE-2003-0072 be exploited locally or remotely?
CVE-2003-0072 can only be exploited remotely by authenticated users within the same realm.