4.4
CVSSv2

CVE-2008-3825

Published: 03/10/2008 Updated: 11/10/2018
CVSS v2 Base Score: 4.4 | Impact Score: 6.4 | Exploitability Score: 3.4
VMScore: 392
Vector: AV:L/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

pam_krb5 2.2.14 in Red Hat Enterprise Linux (RHEL) 5 and previous versions, when the existing_ticket option is enabled, uses incorrect privileges when reading a Kerberos credential cache, which allows local users to gain privileges by setting the KRB5CCNAME environment variable to an arbitrary cache filename and running the (1) su or (2) sudo program. NOTE: there may be a related vector involving sshd that has limited relevance.

Vulnerable Product Search on Vulmon Subscribe to Product

redhat enterprise linux 5

redhat enterprise linux desktop 5

Vendor Advisories

Synopsis Moderate: pam_krb5 security update Type/Severity Security Advisory: Moderate Topic An updated pam_krb5 package that fixes a security issue is now availablefor Red Hat Enterprise Linux 5This update has been rated as having moderate security impact by the RedHat Security Response Team Desc ...