pam_krb5 Existing Ticket Configuration Option Local Privilege Escalation Vulnerability
BID:31534
Info
pam_krb5 Existing Ticket Configuration Option Local Privilege Escalation Vulnerability
| Bugtraq ID: | 31534 |
| Class: | Design Error |
| CVE: |
CVE-2008-3825 |
| Remote: | No |
| Local: | Yes |
| Published: | Oct 02 2008 12:00AM |
| Updated: | Apr 13 2015 09:35PM |
| Credit: | Stéphane Bertin |
| Vulnerable: |
VMWare ESX Server 4.1 SuSE SUSE Linux Enterprise Server 10 S.u.S.E. openSUSE 11.0 S.u.S.E. openSUSE 10.3 S.u.S.E. openSUSE 10.2 rPath rPath Linux 2 Redhat Enterprise Linux Desktop 5 client Redhat Enterprise Linux 5 Server pam_krb5 pam_krb5 0 Mandriva Linux Mandrake 2008.1 x86_64 Mandriva Linux Mandrake 2008.1 Mandriva Linux Mandrake 2008.0 x86_64 Mandriva Linux Mandrake 2008.0 Mandriva Linux Mandrake 2007.1 x86_64 Mandriva Linux Mandrake 2007.1 |
| Not Vulnerable: |
VMWare ESX Server 4.1 ESX410-201101201 |
Discussion
pam_krb5 Existing Ticket Configuration Option Local Privilege Escalation Vulnerability
The 'pam_krb5' module is prone to a local privilege-escalation vulnerability.
Local attackers can exploit this issue to gain elevated privileges on the affected computer.
The 'pam_krb5' module is prone to a local privilege-escalation vulnerability.
Local attackers can exploit this issue to gain elevated privileges on the affected computer.
Exploit / POC
pam_krb5 Existing Ticket Configuration Option Local Privilege Escalation Vulnerability
Attackers can use readily available command-line utilities to exploit this issue.
Attackers can use readily available command-line utilities to exploit this issue.
Solution / Fix
pam_krb5 Existing Ticket Configuration Option Local Privilege Escalation Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
pam_krb5 Existing Ticket Configuration Option Local Privilege Escalation Vulnerability
References:
References:
- pam_krb5 SourceForge Page (pam_krb5)
- (CVE-2008-3825) CVE-2008-3825 pam_krb5 existing_ticket permission flaw (Josh Bressers)