CVE-2009-0360
Summary
| CVE | CVE-2009-0360 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2009-02-13 17:30:00 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | Russ Allbery pam-krb5 before 3.13, when linked against MIT Kerberos, does not properly initialize the Kerberos libraries for setuid use, which allows local users to gain privileges by pointing an environment variable to a modified Kerberos configuration file, and then launching a PAM-based setuid application. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
LocalAccess Complexity
HighAuthentication
NoneConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:L/AC:H/Au:N/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Eyrie | Pam-krb5 | 2.0 | All | All | All |
| Application | Eyrie | Pam-krb5 | 2.1 | All | All | All |
| Application | Eyrie | Pam-krb5 | 2.2 | All | All | All |
| Application | Eyrie | Pam-krb5 | 2.3 | All | All | All |
| Application | Eyrie | Pam-krb5 | 2.4 | All | All | All |
| Application | Eyrie | Pam-krb5 | 2.5 | All | All | All |
| Application | Eyrie | Pam-krb5 | 2.6 | All | All | All |
| Application | Eyrie | Pam-krb5 | 3.0 | All | All | All |
| Application | Eyrie | Pam-krb5 | 3.1 | All | All | All |
| Application | Eyrie | Pam-krb5 | 3.10 | All | All | All |
| Application | Eyrie | Pam-krb5 | 3.11 | All | All | All |
| Application | Eyrie | Pam-krb5 | 3.2 | All | All | All |
| Application | Eyrie | Pam-krb5 | 3.3 | All | All | All |
| Application | Eyrie | Pam-krb5 | 3.4 | All | All | All |
| Application | Eyrie | Pam-krb5 | 3.5 | All | All | All |
| Application | Eyrie | Pam-krb5 | 3.6 | All | All | All |
| Application | Eyrie | Pam-krb5 | 3.7 | All | All | All |
| Application | Eyrie | Pam-krb5 | 3.8 | All | All | All |
| Application | Eyrie | Pam-krb5 | 3.9 | All | All | All |
| Application | Eyrie | Pam-krb5 | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Webmail - OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| Avaya CMS Solaris Kerberos PAM Module Privilege Escalation - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Debian -- Security Information -- DSA-1721-1 libpam-krb5 | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | |
| USN-719-1: pam-krb5 vulnerabilities | Ubuntu | af854a3a-2127-422b-91ae-364da2661108 | www.ubuntu.com | |
| Gentoo update for pam_krb5 - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | |
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| pam-krb5 Lets Local Users Gain Elevated Privileges - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | securitytracker.com | |
| pam-krb5 2009-02-11 Advisory | af854a3a-2127-422b-91ae-364da2661108 | www.eyrie.org | Vendor Advisory |
| ASA-2009-070 (SUN 252767) | af854a3a-2127-422b-91ae-364da2661108 | support.avaya.com | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| Gentoo Linux Documentation -- pam_krb5: Privilege escalation | af854a3a-2127-422b-91ae-364da2661108 | security.gentoo.org | |
| pam-krb5 File Overwrite and Privilege Escalation - Secunia Advisories - Vulnerability Information - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | |
| #252767: A Security Vulnerability in the Solaris Kerberos PAM Module May Allow Use of a User Specified Kerberos Configuration File, Leading to Escalation of Privileges | af854a3a-2127-422b-91ae-364da2661108 | sunsolve.sun.com | |
| Debian update for libpam-krb5 - Secunia Advisories - Vulnerability Intelligence - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| pam-krb5 Local Privilege Escalation Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
| Organization | Published | Contributor | Statement |
|---|---|---|---|
| Red Hat | 2009-02-13 | Joshua Bressers | Not vulnerable. This issue did not affect the versions of the pam_krb5 package, as shipped with Red Hat Enterprise Linux 2.1, 3, 4, or 5. |
There are currently no legacy QID mappings associated with this CVE.