PT-2002-1776 · Mit+1 · Kerberos 5+1

Published

2002-08-12

·

Updated

2008-09-05

·

CVE-2002-0755

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions FreeBSD versions 4.5 and earlier k5su in Kerberos 5
Description The issue is related to the k5su component in Kerberos 5, which does not properly verify user membership in the wheel group before granting superuser privileges. This could potentially allow unauthorized users to execute commands as root.
Recommendations For FreeBSD versions 4.5 and earlier, update to a version that includes the fix for this issue. For k5su in Kerberos 5, ensure that proper group membership verification is implemented to prevent unauthorized access to superuser privileges.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2002-0755

Affected Products

Freebsd
Kerberos 5