PT-2009-1024 · Mit · Pam Krb5+1

Derek Chan

·

Published

2009-02-13

·

Updated

2018-10-11

·

CVE-2009-0361

CVSS v2.0

6.2

Medium

VectorAV:L/AC:H/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions libpam-krb5 versions prior to 3.13 pam-krb5 versions prior to 3.13
Description The issue concerns multiple vulnerabilities in the libpam-krb5 package, which can be exploited by a local attacker to compromise the confidentiality, integrity, and availability of protected information. Specifically, the vulnerability allows local users to overwrite and change the ownership of arbitrary files by setting the KRB5CCNAME environment variable and then launching a setuid application that performs certain pam setcred operations.
Recommendations For libpam-krb5 versions prior to 3.13, update to version 3.13 or later to resolve the issue. For pam-krb5 versions prior to 3.13, update to version 3.13 or later to resolve the issue. As a temporary workaround, consider restricting the use of the pam setcred operation in setuid applications to minimize the risk of exploitation.

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-03045
CVE-2009-0361
DSA-1721-1
DSA-1722-1

Affected Products

Libpam-Krb5
Pam Krb5