SB2011011904 - Multiple vulnerabilities in HP-UX Running Kerberos



SB2011011904 - Multiple vulnerabilities in HP-UX Running Kerberos

Published: January 19, 2011 Updated: April 28, 2023

Security Bulletin ID SB2011011904
Severity
High
Patch available
YES
Number of vulnerabilities 2
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

High 50% Low 50%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 2 secuirty vulnerabilities.


1) Cryptographic issues (CVE-ID: CVE-2010-1323)

The vulnerability allows a remote attacker to escalate privileges on the target system.

The vulnerability exists due to MIT Kerberos 5 does not properly determine the acceptability of checksums. A remote attacker can modify user-visible prompt text, modify a response to a Key Distribution Center (KDC), or forge a KRB-SAFE message via certain checksums that are unkeyed or use RC4 keys.


2) Cryptographic issues (CVE-ID: CVE-2010-1324)

The vulnerability allows a remote attacker to modify files on the system.

The vulnerability exists due to MIT Kerberos 5 does not properly determine the acceptability of checksums. A remote attacker can forge GSS tokens, gain privileges, or have unspecified other impact via an unkeyed checksum, an unkeyed PAC checksum, or a KrbFastArmoredReq checksum based on an RC4 key.


Remediation

Install update from vendor's website.