SkipNavigation
US-CERT
American Flag
  Vulnerability
Notes
Database

Search Vulnerability Notes

Vulnerability Notes Help Information


 
 View Notes By
  Name

ID Number

CVE Name

Date Public

Date Published

Date Updated

Severity Metric



 Other Documents
  Technical Alerts

Technical Bulletins

Alerts

Security Tips

 

Vulnerability Note VU#442569

MIT Kerberos vulnerable to ticket splicing when using Kerberos4 triple DES service tickets

Overview

Several cryptographic vulnerabilities exist in the basic Kerberos version 4 protocol that could allow an attacker to impersonate any user in a Kerberos realm and gain any privilege authorized through that Kerberos realm.

I. Description

The MIT Kerberos Development team has discovered a serious cryptographic flaw in the Kerberos version 4 protocol. This flaw could allow an attacker to compromise the entire affected Kerberos realm. In addition to the vulnerability described in VU#623217, an additional vulnerability was discovered in the MIT Kerberos implementation of triple-DES encryption of service tickets.

From the MIT advisory:

    "As a result of concerns about single DES weaknesses, MIT implemented support for Kerberos 4 tickets encrypted in triple DES service keys. This support shares all the cryptographic weaknesses of single DES Kerberos 4. In addition, since it uses CBC mode rather than PCBC mode, it introduces new weaknesses not found in other Kerberos 4 implementations. When certain alignment constraints are met, it is possible to splice two tickets together, allowing an attacker to get a ticket with a known session key for a client without knowing that client's long term key. This attack does require sniffing a ticket for that client."
As a result, MIT implementations of Kerberos version 5 or derived implementations that include support for triple-DES keys in Kerberos version 4 are vulnerable.

II. Impact

In addition to the impacts described for VU#623217, an attacker may impersonate any principal to a service keyed with triple-DES Kerberos version 4 keys, given the ability to capture network traffic containing tickets for the target client principal.

III. Solution

Apply a patch from the vendor


The MIT Kerberos team has released MIT krb5 Security Advisory 2003-004 regarding this vulnerability. Sites are strongly encouraged to apply the patches referenced in the advisory.
Workarounds

In the absence of patching, the following workarounds have been proposed by the MIT Kerberos team:

1) V4 Cross Realm Considered Harmful

    Kerberos implementations should gain an option to
   disable Kerberos 4 cross-realm authentication both in the KDC and
   in any implementations of the krb524 protocol.  This configuration
   should be the default.

2)  Application Migration

    Application vendors and sites should migrate from Kerberos version 4
   to Kerberos version 5.  The OpenAFS community has introduced features
   that allow Kerberos 5 to be used for AFS in OpenAFS 1.2.8.  Patches
   are available to add Kerberos 5 support to OpenSSH.  Several other
   implementations of the SSH protocol also support Kerberos 5.
   Applications such as IMAP, POP and LDAP already support Kerberos 5.

3) TGT Key Separation

    One motivation for the V4 triple DES support is that if a single
   DES key  exists for the TGT principal then an attacker can  attack
   that key both for v4 and v5 tickets. Kerberos
   implementations should gain support for a DES TGT key that is used
   for v4 requests but not v5 requests.

4) Remove Triple DES Kerberos 4 Support

    The cut and paste attack is a critical failure in MIT's attempt at
   Kerberos 4 Triple DES.  Even without cross-realm authentication,
   this can be exploited in real-world situations.  As such the
   support for 3DES service keys  should be disabled.

Systems Affected

VendorStatusDate Updated
3ComUnknown10-Mar-2003
Apple Computer Inc.Unknown17-Mar-2003
AT&TUnknown10-Mar-2003
AvayaUnknown10-Mar-2003
BSDIUnknown10-Mar-2003
Cisco Systems Inc.Unknown10-Mar-2003
ConectivaVulnerable9-May-2003
Cray Inc.Unknown21-Mar-2003
D-Link SystemsUnknown10-Mar-2003
Data GeneralUnknown17-Mar-2003
DebianVulnerable31-Mar-2003
F5 NetworksUnknown17-Mar-2003
Foundry Networks Inc.Unknown10-Mar-2003
FreeBSDUnknown10-Mar-2003
FujitsuUnknown17-Mar-2003
Gentoo LinuxVulnerable31-Mar-2003
Guardian Digital Inc. Unknown17-Mar-2003
Hewlett-Packard CompanyUnknown17-Mar-2003
HitachiNot Vulnerable4-Apr-2003
IBM-zSeriesUnknown17-Mar-2003
Ingrian NetworksNot Vulnerable17-Mar-2003
IntelUnknown17-Mar-2003
Juniper NetworksNot Vulnerable17-Mar-2003
KTH KerberosUnknown17-Mar-2003
Lotus SoftwareNot Vulnerable10-Mar-2003
Lucent TechnologiesUnknown10-Mar-2003
MandrakeSoftVulnerable1-Apr-2003
Microsoft CorporationNot Vulnerable20-Mar-2003
MiT Kerberos Development TeamUnknown17-Mar-2003
MontaVista SoftwareUnknown10-Mar-2003
Multi-Tech Systems Inc.Unknown17-Mar-2003
NEC CorporationUnknown17-Mar-2003
NETBSDUnknown17-Mar-2003
NetScreenUnknown10-Mar-2003
Network ApplianceUnknown17-Mar-2003
NeXTUnknown17-Mar-2003
NokiaUnknown17-Mar-2003
Nortel NetworksUnknown17-Mar-2003
OpenAFSUnknown17-Mar-2003
OpenBSDUnknown10-Mar-2003
Openwall GNU/*/LinuxUnknown17-Mar-2003
Red Hat Inc.Vulnerable2-Apr-2003
Redback Networks Inc.Unknown17-Mar-2003
Riverstone NetworksUnknown17-Mar-2003
SequentUnknown17-Mar-2003
SGIUnknown10-Mar-2003
Sony CorporationUnknown17-Mar-2003
Sun Microsystems Inc.Unknown17-Mar-2003
SuSE Inc.Unknown10-Mar-2003
The SCO Group (SCO Linux)Unknown10-Mar-2003
The SCO Group (SCO UnixWare)Unknown10-Mar-2003
UnisysUnknown17-Mar-2003
Wind River Systems Inc.Unknown17-Mar-2003
WirexVulnerable9-Apr-2003
XeroxNot Vulnerable9-May-2003

References


http://web.mit.edu/kerberos/www/advisories/MITKRB5-SA-2003-004-krb4.txt

Credit

The CERT/CC thanks Sam Hartman, Ken Raeburn, and Tom Yu of the Kerberos group at MIT for their detailed analysis and report of this vulnerability.

This document was written by Chad R Dougherty.

Other Information

Date Public03/15/2003
Date First Published03/20/2003 11:49:20 AM
Date Last Updated05/09/2003
CERT Advisory 
CVE NameCAN-2003-0139
US-CERT Technical Alerts 
Metric8.91
Document Revision11

If you have feedback, comments, or additional information about this vulnerability, please send us email.
 

 
Page Corner Image
Copyright 2003 Carnegie Mellon University
Disclaimers and copyright information
Get Adobe Reader Get Adobe Reader