Secunia Logo  


Secunia PSI WorldMap
 
CVE Reference: CVE-2007-3149
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2007-3149

Description:
sudo, when linked with MIT Kerberos 5 (krb5), does not properly check whether a user can currently authenticate to Kerberos, which allows local users to gain privileges, in a manner unintended by the sudo security model, via certain KRB5_ environment variable settings. NOTE: another researcher disputes this vulnerability, stating that the attacker must be "a user, who can already log into your system, and can already use sudo."

CVE Status:
Candidate

References:

SAID
  Secunia Advisory: SA26540

CONFIRM
  http://www.sudo.ws/cgi-bin/cvsweb/sudo/auth/kerb5.c

BUGTRAQ
  http://www.securityfocus.com/archive/1/archive/1/470739/100/0/threaded
  http://www.securityfocus.com/archive/1/archive/1/470774/100/0/threaded
  http://www.securityfocus.com/archive/1/archive/1/470752/100/0/threaded

BID
  24368


Return to the previous page.