CVE-2025-3576

A vulnerability in the MIT Kerberos implementation allows GSSAPI-protected messages using RC4-HMAC-MD5 to be spoofed due to weaknesses in the MD5 checksum design. If RC4 is preferred over stronger encryption types, an attacker could exploit MD5 collisions to forge message integrity codes. This may lead to unauthorized message tampering.
CVSS

No CVSS.

Configurations

No configuration.

History

13 Aug 2025, 09:15

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2025:13777 -

12 Aug 2025, 02:15

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2025:13664 -

28 Jul 2025, 14:15

Type Values Removed Values Added
References
  • () https://web.mit.edu/kerberos/krb5-1.22/krb5-1.22.html -

21 Jul 2025, 20:15

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2025:11487 -

24 Jun 2025, 13:15

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2025:9430 -

24 Jun 2025, 07:15

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2025:9418 -

03 Jun 2025, 03:15

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2025:8411 -

30 May 2025, 17:15

Type Values Removed Values Added
References
  • () https://lists.debian.org/debian-lts-announce/2025/05/msg00047.html -

15 Apr 2025, 18:39

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 5.9
v2 : unknown
v3 : unknown
CWE CWE-328

15 Apr 2025, 06:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-04-15 06:15

Updated : 2025-08-13 09:15


NVD link : CVE-2025-3576

Mitre link : CVE-2025-3576


JSON object : View

Products Affected

No product.

CWE

No CWE.