MIT Kerberos 5 (aka krb5) 1.8.x through 1.8.3 does not reject RC4 key-derivation checksums, which might allow remote authenticated users to forge a (1) AD-SIGNEDPATH or (2) AD-KDC-ISSUED signature, and possibly gain privileges, by leveraging the small key space that results from certain one-byte stream-cipher operations.
CVSS Details
- CVSS 3.1 Base Score: 6.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apple Osx Airport | — | Apply OS X security update 2011-004Apply OS X security update 2011-001Upgrade macOS to the latest version | Aug 28, 2015 | Dec 2, 2010 |
| Apple Osx Kerberos | — | Apply OS X security update 2011-001Upgrade macOS to the latest version | Dec 16, 2011 | Dec 2, 2010 |
| Debian | — | Upgrade krb5 | Jul 30, 2024 | Dec 2, 2010 |
| Freebsd | — | Upgrade krb5 | Dec 10, 2025 | Dec 9, 2010 |
| Gentoo Linux | — | Upgrade app-crypt/mit-krb5. | Oct 30, 2017 | Dec 2, 2010 |
| Oracle Solaris | — | Upgrade system/kernel/security/gss to version 0.5.11-0.175.1.11.0.3.2 on Solaris 11.1Upgrade consolidation/osnet/osnet-incorporation to version 0.5.11-0.175.2.0.0.42.2 on Solaris 11.2 | May 29, 2017 | Dec 2, 2010 |
| Oracle_linux | — | Upgrade krb5-libsUpgrade krb5-serverUpgrade krb5-develUpgrade krb5-pkinit-opensslUpgrade krb5-workstationUpgrade krb5-server-ldap | Oct 16, 2024 | Dec 2, 2010 |
| Suse | — | Upgrade krb5-apps-serversUpgrade krb5-docUpgrade krb5-serverUpgrade krb5-plugin-preauth-pkinitUpgrade krb5Upgrade krb5-develUpgrade krb5-plugin-preauth-spakeUpgrade krb5-apps-clientsUpgrade krb5-clientUpgrade krb5-plugin-kdb-ldapUpgrade krb5-x86Upgrade krb5-plugin-preauth-otpUpgrade krb5-32bit | Feb 17, 2015 | Jun 28, 2013 |
| Ubuntu | — | Upgrade libkrb5-3Upgrade libkrb53 | Nov 8, 2024 | Dec 2, 2010 |
| Vmsa 2011 0007 | — | Upgrade VMware ESXi 4.1 to build number 381591Upgrade VMware ESX 4.1 to build number 381591 | May 12, 2011 | Apr 28, 2011 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub