PT-2008-1073 · Mit+1 · Pam Krb5+1
Publicado
2008-10-02
·
Atualizado
2018-10-11
·
CVE-2008-3825
CVSS v2.0
4.4
Média
| Vetor | AV:L/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
pam krb5 versions 2.2.14 through 2.6.14
Red Hat Enterprise Linux (RHEL) 5 and earlier
Description
The issue allows local users to gain privileges by setting the
KRB5CCNAME environment variable to an arbitrary cache filename and running the (1) su or (2) sudo program. This can lead to a violation of confidentiality, integrity, and availability of protected information. The exploitation can be carried out locally.Recommendations
For pam krb5 version 2.2.14, consider disabling the existing ticket option as a temporary workaround until a patch is available.
For Red Hat Enterprise Linux (RHEL) 5 and earlier, restrict access to the su and sudo programs to minimize the risk of exploitation.
Avoid using the
KRB5CCNAME environment variable in the affected systems until the issue is resolved.Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Red Hat
Pam Krb5