CVE-2012-1012 describes an access restriction vulnerability in MIT Kerberos 5 (krb5) versions prior to 1.10.1, specifically within the kadmin protocol's server/server_stubs.c. This flaw allows remote authenticated administrators with global list privileges to improperly modify or read string attributes using SET_STRING and GET_STRINGS operations. The vulnerability has a CVSS score of 5.5, indicating a medium severity. It is network-exploitable with low attack complexity, requiring authentication, and could lead to partial confidentiality and integrity impacts. There is no impact on availability. There is no evidence of active exploitation, and no public exploit code is available on platforms like Metasploit or ExploitDB. Community discussion and media coverage for this CVE are minimal, suggesting low public attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.10CPE matchmatch criteria | cpe:2.3:a:mit:kerberos_5:1.10:*:*:*:*:*:*:* | ||
1.10.1CPE matchmatch criteria | cpe:2.3:a:mit:kerberos_5:1.10.1:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:S/C:P/I:P/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.