NASLDB: FreeBSD : krb5 -- RFC 3961 key-derivation checksum handling vulnerability (1d193bba-03f6-11e0-bf50-001a926c7637)
General
ID: 51102
Name: FreeBSD : krb5 — RFC 3961 key-derivation checksum handling vulnerability (1d193bba-03f6-11e0-bf50-001a926c7637)
Summary: Checks for updated package in pkg_info output
Credits: Tenable Network Security, Inc.
Classification
Risk: –
CVSS: –
CVSS Base Vector: CVSS2#AV:N/AC:M/Au:S/C:N/I:P/A:N
CVSS Temporal Vector: CVSS2#E:POC/RL:OF/RC:C
Port: 0
Family: FreeBSD Local Security Checks
Type: Local
Description
The MIT Kerberos team reports :
MIT krb5 (releases incorrectly accepts RFC 3961 key-derivation
checksums using RC4 keys when verifying AD-SIGNEDPATH and
AD-KDC-ISSUED authorization data.
An authenticated remote attacker that controls a legitimate service
principal has a 1/256 chance of forging the AD-SIGNEDPATH signature if
the TGT key is RC4, allowing it to use self-generated ‘evidence’
tickets for S4U2Proxy, instead of tickets obtained from the user or
with S4U2Self. Configurations using RC4 for the TGT key are believed
to be rare.
An authenticated remote attacker has a 1/256 chance of forging
AD-KDC-ISSUED signatures on authdata elements in tickets having an RC4
service key, resulting in privilege escalation against a service that
relies on these signatures. There are no known uses of the KDC-ISSUED
authdata container at this time.
Exploiting
Exploit Available: True
Exploitability Ease: Exploits are available
Sources
CVE: CVE-2010-4020
OSVDB: –
Bugtraq: –
scipID: –
Timeline
Vulnerability Disclosure: 2010/11/30
Patch Release: 2010/12/09
Plugin Release: 2010/12/10
Plugin
Version: 1.6
Filename: freebsd_pkg_1d193bba03f611e0bf50001a926c7637.nasl
Filesize: 5295 bytes
MD5 Hash: 2f4b147e47b2a7397a00bd757c4d5ec7
Identification: Host/local_checks_enabled
Require Keys: Host/local_checks_enabled", "Host/FreeBSD/release", "Host/FreeBSD/pkg_info
Dependencies: "ssh_get_info.nasl"
Copyright: This script is© 2010-2012 Tenable Network Security, Inc.
- Latest Plugins
- USN-1611-1 : thunderbird vulnerabilities
- USN-1610-1 : linux vulnerability
- USN-1609-1 : linux-ti-omap4 vulnerability
- SuSE 10 Security Update : PostgreSQL
- RHSA-2012-1364: bind97
- RHSA-2012-1363: bind
- RHSA-2012-1362: thunderbird
- RHSA-2012-1361: xulrunner
- Mandriva Linux Security Advisory : graphicsmagick
- FreeBSD : phpMyAdmin — Multiple XSS due to unescaped HTML output in Trigger, Procedure and Event pages and Fetching the version information from a non-SSL site is vulnerable to a MITM attack













