|
|
| |
|
| |
pam_krb5: privilege elevation
| Package(s): | pam_krb5 |
CVE #(s): | CVE-2008-3825
|
| Created: | October 2, 2008 |
Updated: | January 14, 2009 |
| Description: |
From the Red Hat alert:
A flaw was found in the pam_krb5 "existing_ticket" configuration option. If
a system is configured to use an existing credential cache via the
"existing_ticket" option, it may be possible for a local user to gain
elevated privileges by using a different, local user's credential cache.
(CVE-2008-3825) |
| Alerts: |
|
( Log in to post comments)
|
|
|