PT-2002-1776 · Mit+1 · Kerberos 5+1
Published
2002-08-12
·
Updated
2008-09-05
·
CVE-2002-0755
CVSS v2.0
7.2
High
| Vector | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
FreeBSD versions 4.5 and earlier
k5su in Kerberos 5
Description
The issue is related to the k5su component in Kerberos 5, which does not properly verify user membership in the wheel group before granting superuser privileges. This could potentially allow unauthorized users to execute commands as root.
Recommendations
For FreeBSD versions 4.5 and earlier, update to a version that includes the fix for this issue.
For k5su in Kerberos 5, ensure that proper group membership verification is implemented to prevent unauthorized access to superuser privileges.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Freebsd
Kerberos 5