Lucene search

K
cveMitreCVE-2012-1012
HistoryJun 07, 2012 - 7:55 p.m.

CVE-2012-1012

2012-06-0719:55:07
CWE-264
mitre
web.nvd.nist.gov
33
mit kerberos
krb5
1.10
1.10.1
server_stubs.c
access restriction
vulnerability
nvd
cve-2012-1012

CVSS2

5.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:S/C:P/I:P/A:N

AI Score

6

Confidence

Low

EPSS

0.002

Percentile

61.1%

server/server_stubs.c in the kadmin protocol implementation in MIT Kerberos 5 (aka krb5) 1.10 before 1.10.1 does not properly restrict access to (1) SET_STRING and (2) GET_STRINGS operations, which might allow remote authenticated administrators to modify or read string attributes by leveraging the global list privilege.

Affected configurations

Nvd
Node
mitkerberos_5Match1.10
OR
mitkerberos_5Match1.10.1
VendorProductVersionCPE
mitkerberos_51.10cpe:2.3:a:mit:kerberos_5:1.10:*:*:*:*:*:*:*
mitkerberos_51.10.1cpe:2.3:a:mit:kerberos_5:1.10.1:*:*:*:*:*:*:*

CVSS2

5.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:S/C:P/I:P/A:N

AI Score

6

Confidence

Low

EPSS

0.002

Percentile

61.1%