Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!

Bug 269008

Summary: sys-auth/pam_krb5-3.12: Local privilege escalation, local file overwrite
Product: Gentoo Security Reporter: Oleh Kravchenko <oleg>
Component: VulnerabilitiesAssignee: Gentoo Security <security>
Status: VERIFIED DUPLICATE    
Severity: normal    
Priority: High    
Version: unspecified   
Hardware: All   
OS: Linux   
URL: http://www.eyrie.org/~eagle/software/pam-krb5/security/2009-02-11.html
Whiteboard:
Package list:
Runtime testing required: ---

Description Oleh Kravchenko 2009-05-08 07:35:51 UTC
A security vulnerability in pam-krb5 allowing overwrite and chown of arbitrary files via Solaris su was discovered by Derek Chan and reported by Steven Luo on 2009-01-29. Subsequent code auditing for behavior in setuid applications uncovered another, more general and more serious bug that could result in privilege escalation. 

Reproducible: Always

Steps to Reproduce:
Comment 1 Alex Legler (RETIRED) archtester gentoo-dev Security 2009-05-08 10:26:16 UTC
These issues were addressed in GLSA 200903-39.

Please do a search before posting new bugs (and be sure to include closed bugs, too).

*** This bug has been marked as a duplicate of bug 257075 ***