Junglewise Threat Intelligence

CVE-1999-0143: MIT Kerberos 4 session key forgery and masquerade

CVE-1999-0143 · Severity: medium · CVSS 4.6 · Published 1996-02-21

Vendors: Mit, Sun Microsystems.

Executive brief

A security flaw in the Kerberos 4 authentication system allows an attacker to impersonate other users. Kerberos is a service used to verify identities across a network; by breaking and generating session keys, an unauthorized person could gain access to sensitive data or systems by pretending to be a legitimate user. This could lead to unauthorized data access and a breach of accountability within the organization.

Technical details

A vulnerability exists in Kerberos 4 key servers related to the generation and handling of session keys. An attacker with local access can exploit weaknesses in the key generation process to derive or forge session keys. Successful exploitation allows the attacker to masquerade as any other user within the Kerberos realm, bypassing standard authentication controls. This issue affects MIT Kerberos 4 implementations and integrated versions found in legacy operating systems like SunOS and Solaris. Modern versions of Kerberos (v5) address these fundamental cryptographic weaknesses.

Affected products

  • MIT Kerberos 4
  • Sun Microsystems Solaris 2.3, 2.4
  • Sun Microsystems SunOS 5.3, 5.4

Timeline

  • 1996-02-21: disclosed: Initial publication date in NVD

References

Related threats