First published: Fri Mar 21 2003(Updated: )
Version 4 of the Kerberos protocol (krb4), as used in Heimdal and other packages, allows an attacker to impersonate any principal in a realm via a chosen-plaintext attack.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
MIT Kerberos 5 | =4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2003-0138 is considered a high-severity vulnerability due to the potential for an attacker to impersonate any principal.
To fix CVE-2003-0138, upgrade to a version of Kerberos that does not include the vulnerable krb4 implementation.
CVE-2003-0138 affects systems using Version 4 of the Kerberos protocol, specifically implementations that utilize krb4.
CVE-2003-0138 can be exploited through a chosen-plaintext attack, allowing an attacker to impersonate any principal in the realm.
While CVE-2003-0138 primarily affects older versions of Kerberos, any legacy systems still using krb4 may still be vulnerable.