pam_krb5 2.2.14 in Red Hat Enterprise Linux (RHEL) 5 and earlier, when the existing_ticket option is enabled, uses incorrect privileges when reading a Kerberos credential cache, which allows local users to gain privileges by setting the KRB5CCNAME environment variable to an arbitrary cache filename and running the (1) su or (2) sudo program. NOTE: there may be a related vector involving sshd that has limited relevance.
CVSS Details
- CVSS 3.1 Base Score: 8.4
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade pam_krb5 | Dec 1, 2016 | Oct 3, 2008 |
| Oracle_linux | — | Upgrade pam_krb5 | Oct 16, 2024 | Oct 3, 2008 |
| Suse | — | Upgrade pam_krb5-x86Upgrade pam_krb5-32bitUpgrade pam_krb5 | Feb 17, 2015 | Jul 9, 2013 |
| Vmsa 2011 0003 | — | Upgrade VMware ESX 4.1 to build number 348481 | Feb 16, 2011 | Oct 3, 2008 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub