PT-2009-1024 · Mit · Pam Krb5+1

Derek Chan

·

Publicado

2009-02-13

·

Atualizado

2018-10-11

·

CVE-2009-0361

CVSS v2.0

6.2

Média

VetorAV:L/AC:H/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions libpam-krb5 versions prior to 3.13 pam-krb5 versions prior to 3.13
Description The issue concerns multiple vulnerabilities in the libpam-krb5 package, which can be exploited by a local attacker to compromise the confidentiality, integrity, and availability of protected information. Specifically, the vulnerability allows local users to overwrite and change the ownership of arbitrary files by setting the KRB5CCNAME environment variable and then launching a setuid application that performs certain pam setcred operations.
Recommendations For libpam-krb5 versions prior to 3.13, update to version 3.13 or later to resolve the issue. For pam-krb5 versions prior to 3.13, update to version 3.13 or later to resolve the issue. As a temporary workaround, consider restricting the use of the pam setcred operation in setuid applications to minimize the risk of exploitation.

Correção

Improper Authentication

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-03045
CVE-2009-0361
DSA-1721-1
DSA-1722-1

Produtos afetados

Libpam-Krb5
Pam Krb5