PT-2007-4432 · Mit+2 · Mit Kerberos 5+2

Published

2007-06-11

·

Updated

2020-01-21

·

CVE-2007-3149

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: sudo (affected versions not specified)
Description: The issue concerns sudo when linked with MIT Kerberos 5 (krb5), where it does not properly check whether a user can currently authenticate to Kerberos. This allows local users to gain privileges in a manner unintended by the sudo security model via certain KRB5 environment variable settings.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

ALT-PU-2017-1056
CVE-2007-3149

Affected Products

Alt Linux
Mit Kerberos 5
Sudo