Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 269008 - sys-auth/pam_krb5-3.12: Local privilege escalation, local file overwrite
Summary: sys-auth/pam_krb5-3.12: Local privilege escalation, local file overwrite
Status: VERIFIED DUPLICATE of bug 257075
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High normal (vote)
Assignee: Gentoo Security
URL: http://www.eyrie.org/~eagle/software/...
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2009-05-08 07:35 UTC by Oleh Kravchenko
Modified: 2010-02-24 23:18 UTC (History)
0 users

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Oleh Kravchenko 2009-05-08 07:35:51 UTC
A security vulnerability in pam-krb5 allowing overwrite and chown of arbitrary files via Solaris su was discovered by Derek Chan and reported by Steven Luo on 2009-01-29. Subsequent code auditing for behavior in setuid applications uncovered another, more general and more serious bug that could result in privilege escalation. 

Reproducible: Always

Steps to Reproduce:
Comment 1 Alex Legler (RETIRED) archtester gentoo-dev Security 2009-05-08 10:26:16 UTC
These issues were addressed in GLSA 200903-39.

Please do a search before posting new bugs (and be sure to include closed bugs, too).

*** This bug has been marked as a duplicate of bug 257075 ***