LWN.net Logo

pam_krb5: privilege elevation

Package(s):pam_krb5 CVE #(s):CVE-2008-3825
Created:October 2, 2008 Updated:January 14, 2009
Description: From the Red Hat alert:

A flaw was found in the pam_krb5 "existing_ticket" configuration option. If a system is configured to use an existing credential cache via the "existing_ticket" option, it may be possible for a local user to gain elevated privileges by using a different, local user's credential cache. (CVE-2008-3825)

Alerts:
SuSE SUSE-SR:2008:027 2008-12-09
rPath rPSA-2009-0007-1 2009-01-13
Mandriva MDVSA-2008:209 2007-10-03
Fedora FEDORA-2008-8618 2008-10-03
Fedora FEDORA-2008-8605 2008-10-03
CentOS CESA-2008:0907 2008-10-05
Red Hat RHSA-2008:0907-01 2008-10-02

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds