MIT KRB5 Security Advisory 2003-004 – A cryptographic weakness in version 4 of the Kerberos protocol allows an attacker to use a chosen-plaintext attack to impersonate any principal in a realm. Additional cryptographic weaknesses in the krb4 implementation included in the MIT krb5 distribution permit the use of cut-and-paste attacks to fabricate krb4 tickets for unauthorized client principals, effectively subverting a site’s entire Kerberos authentication infrastructure. Patch available here.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/30920/MITKRB5-SA-2003-004-krb4.txt
Source: https://packetstormsecurity.com/files/30920/MITKRB5-SA-2003-004-krb4.txt.html

