5.5
CVSSv2

CVE-2012-1012

Published: 07/06/2012 Updated: 21/01/2020
CVSS v2 Base Score: 5.5 | Impact Score: 4.9 | Exploitability Score: 8
VMScore: 490
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:N

Vulnerability Summary

server/server_stubs.c in the kadmin protocol implementation in MIT Kerberos 5 (aka krb5) 1.10 prior to 1.10.1 does not properly restrict access to (1) SET_STRING and (2) GET_STRINGS operations, which might allow remote authenticated administrators to modify or read string attributes by leveraging the global list privilege.

Vulnerable Product Search on Vulmon Subscribe to Product

mit kerberos 5 1.10

mit kerberos 5 1.10.1

Vendor Advisories

Debian Bug report logs - #670918 CVE-2012-1012 Package: krb5; Maintainer for krb5 is Sam Hartman <hartmans@debianorg>; Reported by: Moritz Muehlenhoff <muehlenhoff@univentionde> Date: Mon, 30 Apr 2012 12:33:27 UTC Severity: normal Tags: security Found in version 110+dfsg~beta1-2 Fixed in version krb5/1101+dfsg- ...
Several security issues were fixed in Kerberos ...