PT-2002-1776 · Mit+1 · Kerberos 5+1

Publicado

2002-08-12

·

Atualizado

2008-09-05

·

CVE-2002-0755

CVSS v2.0

7.2

Alta

VetorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions FreeBSD versions 4.5 and earlier k5su in Kerberos 5
Description The issue is related to the k5su component in Kerberos 5, which does not properly verify user membership in the wheel group before granting superuser privileges. This could potentially allow unauthorized users to execute commands as root.
Recommendations For FreeBSD versions 4.5 and earlier, update to a version that includes the fix for this issue. For k5su in Kerberos 5, ensure that proper group membership verification is implemented to prevent unauthorized access to superuser privileges.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2002-0755

Produtos afetados

Freebsd
Kerberos 5