CVE
- Id
- 46605
- CVE No.
- CVE-2010-4021
- Status
- Candidate
- Description
- The Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.7 does not properly restrict the use of TGT credentials for armoring TGS requests, which might allow remote authenticated users to impersonate a client by rewriting an inner request, aka a "KrbFastReq forgery issue."
- Phase
- Assigned (20101020)
- Votes
- None (candidate not yet proposed)
- Comments
Related CVE References
Id | CVE Id | CVE No. | Reference | Actions |
---|---|---|---|---|
508934 | 46605 | CVE-2010-4021 | BUGTRAQ:20101130 MITKRB5-SA-2010-007 Multiple checksum handling vulnerabilities [CVE-2010-1324 CVE-2010-1323 CVE-2010-4020 CVE-2010-4021] | View |
508935 | 46605 | CVE-2010-4021 | URL:http://www.securityfocus.com/archive/1/archive/1/514953/100/0/threaded | View |
508936 | 46605 | CVE-2010-4021 | BUGTRAQ:20110428 VMSA-2011-0007 VMware ESXi and ESX Denial of Service and third party updates for Likewise components and ESX Service Console | View |
508937 | 46605 | CVE-2010-4021 | URL:http://www.securityfocus.com/archive/1/archive/1/517739/100/0/threaded | View |
508938 | 46605 | CVE-2010-4021 | MLIST:[security-announce] 20110428 VMSA-2011-0007 VMware ESXi and ESX Denial of Service and third party updates for Likewise components and ESX Service Console | View |
508939 | 46605 | CVE-2010-4021 | URL:http://lists.vmware.com/pipermail/security-announce/2011/000133.html | View |
508940 | 46605 | CVE-2010-4021 | CONFIRM:http://web.mit.edu/kerberos/advisories/MITKRB5-SA-2010-007.txt | View |
508941 | 46605 | CVE-2010-4021 | CONFIRM:http://support.apple.com/kb/HT4581 | View |
508942 | 46605 | CVE-2010-4021 | CONFIRM:http://kb.vmware.com/kb/1035108 | View |
508943 | 46605 | CVE-2010-4021 | CONFIRM:http://www.vmware.com/security/advisories/VMSA-2011-0007.html | View |
508944 | 46605 | CVE-2010-4021 | APPLE:APPLE-SA-2011-03-21-1 | View |
508945 | 46605 | CVE-2010-4021 | URL:http://lists.apple.com/archives/security-announce/2011/Mar/msg00006.html | View |
508946 | 46605 | CVE-2010-4021 | MANDRIVA:MDVSA-2010:246 | View |
508947 | 46605 | CVE-2010-4021 | URL:http://www.mandriva.com/security/advisories?name=MDVSA-2010:246 | View |
508948 | 46605 | CVE-2010-4021 | SUSE:SUSE-SR:2010:023 | View |
508949 | 46605 | CVE-2010-4021 | URL:http://lists.opensuse.org/opensuse-security-announce/2010-12/msg00000.html | View |
508950 | 46605 | CVE-2010-4021 | SUSE:SUSE-SR:2010:024 | View |
508951 | 46605 | CVE-2010-4021 | URL:http://lists.opensuse.org/opensuse-security-announce/2010-12/msg00006.html | View |
508952 | 46605 | CVE-2010-4021 | UBUNTU:USN-1030-1 | View |
508953 | 46605 | CVE-2010-4021 | URL:http://www.ubuntu.com/usn/USN-1030-1 | View |
508954 | 46605 | CVE-2010-4021 | BID:45122 | View |
508955 | 46605 | CVE-2010-4021 | URL:http://www.securityfocus.com/bid/45122 | View |
508956 | 46605 | CVE-2010-4021 | OSVDB:69607 | View |
508957 | 46605 | CVE-2010-4021 | URL:http://osvdb.org/69607 | View |
508958 | 46605 | CVE-2010-4021 | SECTRACK:1024803 | View |
508959 | 46605 | CVE-2010-4021 | URL:http://www.securitytracker.com/id?1024803 | View |
508960 | 46605 | CVE-2010-4021 | VUPEN:ADV-2010-3094 | View |
508961 | 46605 | CVE-2010-4021 | URL:http://www.vupen.com/english/advisories/2010/3094 | View |
508962 | 46605 | CVE-2010-4021 | VUPEN:ADV-2010-3118 | View |
Related JVN
Id | JVN No. | Title | Summary | CVE No. | CVE Id | CVSS_v2 | CVSS_v3 | JVN URL | Actions |
---|---|---|---|---|---|---|---|---|---|
37518 | JVNDB-2010-003303 | HP Palm webOS の Doc Viewer における任意のコードを実行される脆弱性 | HP Palm webOS の Doc Viewer には、任意のコードを実行される脆弱性が存在します。 | CVE-2010-4025 | 46605 | 9.3 | http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-003303.html | View |