MIT Kerberos 5 (krb5) contains a flaw related to the Key Distrubiton Center (KDC). The KDC does not properly restrict the use of TGT credentials for armoring TGS requests. The issue is triggered when a remote, authenticated attacker rewrites an inner request (or 'KrbFastReq Forgery Issue']. This may allow the attacker to impersonate a client.
Currently, there are no known workarounds or upgrades to correct this issue. However, MIT has released a patch to address this vulnerability. Check the vendor advisory or solution in the references section.