6.2
CVSSv2

CVE-2009-0360

Published: 13/02/2009 Updated: 11/10/2018
CVSS v2 Base Score: 6.2 | Impact Score: 10 | Exploitability Score: 1.9
VMScore: 625
Vector: AV:L/AC:H/Au:N/C:C/I:C/A:C

Vulnerability Summary

Russ Allbery pam-krb5 prior to 3.13, when linked against MIT Kerberos, does not properly initialize the Kerberos libraries for setuid use, which allows local users to gain privileges by pointing an environment variable to a modified Kerberos configuration file, and then launching a PAM-based setuid application.

Vulnerable Product Search on Vulmon Subscribe to Product

eyrie pam-krb5 3.8

eyrie pam-krb5 3.7

eyrie pam-krb5 3.0

eyrie pam-krb5 2.6

eyrie pam-krb5

eyrie pam-krb5 3.11

eyrie pam-krb5 3.4

eyrie pam-krb5 3.3

eyrie pam-krb5 2.3

eyrie pam-krb5 2.2

eyrie pam-krb5 3.10

eyrie pam-krb5 3.9

eyrie pam-krb5 3.2

eyrie pam-krb5 3.1

eyrie pam-krb5 2.1

eyrie pam-krb5 2.0

eyrie pam-krb5 3.6

eyrie pam-krb5 3.5

eyrie pam-krb5 2.5

eyrie pam-krb5 2.4

Vendor Advisories

Debian Bug report logs - #516695 libpam-heimdal: new version (313) fixing two security issues Package: libpam-heimdal; Maintainer for libpam-heimdal is Russ Allbery <rra@debianorg>; Source for libpam-heimdal is src:libpam-krb5 (PTS, buildd, popcon) Reported by: Richard A Nelson <cowboy@debianorg> Date: Mon, 23 Feb ...
It was discovered that pam_krb5 parsed environment variables when run with setuid applications A local attacker could exploit this flaw to bypass authentication checks and gain root privileges (CVE-2009-0360) ...
Several local vulnerabilities have been discovered in the PAM module for MIT Kerberos The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2009-0360 Russ Allbery discovered that the Kerberos PAM module parsed configuration settings from environment variables when run from a setuid context This could le ...

Exploits

/* * cve-2009-0360c * * pam-krb5 < 313 local privilege escalation * Jon Oberheide <jon@oberheideorg> * jonoberheideorg * * Information: * * cvemitreorg/cgi-bin/cvenamecgi?name=CVE-2009-0360 * * pam-krb5 before 313, when linked against MIT Kerberos, does not properly * initialize the Kerberos librar ...
pam-krb5 versions below 313 local privilege escalation exploit ...