CVE-2003-0139
Certain weaknesses in the implementation of version 4 of the Kerberos protocol (krb4) in the krb5 distribution, when triple-DES keys are used to key krb4 services, allow an attacker to create krb4 tickets for unauthorized principals using a cut-and-paste attack and "ticket splicing."
Scoring
- CVSS base score
- 0.2
- EPSS probability
- 4.95%
- Published
- 2003-03-21
- Last modified
- 2026-03-16
Affected products
- n/a n/a