MEDIUM · 6.2

CVE-2009-0360

Russ Allbery pam-krb5 before 3.13, when linked against MIT Kerberos, does not properly initialize the Kerberos libraries for setuid use, which allows local users to gain privileges by pointing an envi...

Vulnerability Description

Russ Allbery pam-krb5 before 3.13, when linked against MIT Kerberos, does not properly initialize the Kerberos libraries for setuid use, which allows local users to gain privileges by pointing an environment variable to a modified Kerberos configuration file, and then launching a PAM-based setuid application.

CVSS Score

6.2

MEDIUM

AV:L/AC:H/Au:N/C:C/I:C/A:C
Confidentiality
COMPLETE
Integrity
COMPLETE
Availability
COMPLETE

Affected Products

VendorProductVersions
EyriePam-Krb5<= 3.12

Related Weaknesses (CWE)

References

FAQ

What is CVE-2009-0360?

CVE-2009-0360 is a vulnerability with a CVSS score of 6.2 (MEDIUM). Russ Allbery pam-krb5 before 3.13, when linked against MIT Kerberos, does not properly initialize the Kerberos libraries for setuid use, which allows local users to gain privileges by pointing an envi...

How severe is CVE-2009-0360?

CVE-2009-0360 has been rated MEDIUM with a CVSS base score of 6.2/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2009-0360?

Check the references section above for vendor advisories and patch information. Affected products include: Eyrie Pam-Krb5.