CVE-2010-1323: Low severity kerberos vulnerability
MIT Kerberos 5 (aka krb5) 1.3.x, 1.4.x, 1.5.x, 1.6.x, 1.7.x, and 1.8.x through 1.8.3 does not properly determine the acceptability of checksums, which might allow remote attackers to modify user-visible prompt text, modify a response to a Key Distribution Center (KDC), or forge a KRB-SAFE message via certain checksums that (1) are unkeyed or (2) use RC4 keys.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2010-1323?
CVE-2010-1323 has a medium severity rating due to its potential to allow remote attackers to forge messages and modify user-visible prompt text.
How do I fix CVE-2010-1323?
To fix CVE-2010-1323, upgrade to a version of MIT Kerberos 5 that is not affected, such as 1.8.4 or later.
What versions of MIT Kerberos 5 are affected by CVE-2010-1323?
Versions 1.3.x through 1.8.3 of MIT Kerberos 5 are affected by CVE-2010-1323.
What types of attacks can be executed due to CVE-2010-1323?
CVE-2010-1323 can allow remote attackers to forge KRB-SAFE messages and alter responses to the Key Distribution Center.
Is there a workaround for CVE-2010-1323 if I can't upgrade?
There are no known workarounds for CVE-2010-1323; upgrading to a patched version is recommended.