Vulnerability Scanning Solutions, LLC.
Our Process
What We Scan For
Sample Report
Client List
Contact Us
What We Scan For
Family: Debian Local Security Checks --> Category: infos

[DSA1146] DSA-1146-1 krb5 Vulnerability Scan

Vulnerability Scan Summary
DSA-1146-1 krb5

Detailed Explanation for this Vulnerability Test

In certain application programs packaged in the MIT Kerberos 5 source
distribution, calls to setuid() and seteuid() are not always checked
for success and may fail with some PAM configurations. A local
user could exploit one of these vulnerabilities to result in privilege
escalation. No exploit code is known to exist at this time.
For the stable distribution (sarge) these problems have been fixed in
version 1.3.6-2sarge3.
For the unstable distribution (sid) these problems have been fixed in
version 1.4.3-9.
We recommend that you upgrade your krb5 packages.

Solution :
Threat Level: High

Click HERE for more information and discussions on this network vulnerability scan.


P.O. Box 827051

Pembroke Pines, FL 33082-7051

Vulnerability Scanning Solutions, LLC.