AIX Kerberos 5 Vulnerability
BID:436
Info
AIX Kerberos 5 Vulnerability
| Bugtraq ID: | 436 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Jul 02 1998 12:00AM |
| Updated: | Jul 02 1998 12:00AM |
| Credit: | This vulnerability was published to the IBM APAR Database on July 2, 1998. The SecurityFocus Database entry for this problem is based wholly off that information. |
| Vulnerable: |
IBM AIX 4.3 |
| Not Vulnerable: |
IBM AIX 4.3.2 IBM AIX 4.2.1 IBM AIX 4.2 IBM AIX 4.1.5 IBM AIX 4.1.4 IBM AIX 4.1.3 IBM AIX 4.1.2 IBM AIX 4.1.1 IBM AIX 4.1 IBM AIX 3.2.5 |
Discussion
AIX Kerberos 5 Vulnerability
Under AIX 3.0 a user can imitate another user's Kerberos credentials by modifying the KRB5CCNAME environment variable.
Under AIX 3.0 a user can imitate another user's Kerberos credentials by modifying the KRB5CCNAME environment variable.
Exploit / POC
AIX Kerberos 5 Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Solution / Fix
AIX Kerberos 5 Vulnerability
Solution:
IBM has released the following APAR'S to address this problem:
AIX 4.3
---------
APAR # IX79857
Solution:
IBM has released the following APAR'S to address this problem:
AIX 4.3
---------
APAR # IX79857
References
AIX Kerberos 5 Vulnerability
References:
References:
- AIX Fix Distribution Service (IBM)
- IBM Support Databases (IBM)