|
Family: Gentoo Local Security Checks --> Category: infos
[GLSA-200608-15] MIT Kerberos 5: Multiple local privilege escalation vulnerabilities Vulnerability Scan
Vulnerability Scan Summary MIT Kerberos 5: Multiple local privilege escalation vulnerabilities
Detailed Explanation for this Vulnerability Test
The remote host is affected by the vulnerability described in GLSA-200608-15
(MIT Kerberos 5: Multiple local privilege escalation vulnerabilities)
Unchecked calls to setuid() in krshd and v4rcp, as well as unchecked
calls to seteuid() in kftpd and in ksu, have been found in the MIT
Kerberos 5 program suite and may lead to a local root privilege
escalation.
Impact
A local attacker could exploit this vulnerability to execute arbitrary
code with elevated rights.
Workaround
There is no known workaround at this time.
References:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3083
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3084
Solution:
All MIT Kerberos 5 users should upgrade to the latest version:
# emerge --sync
# emerge --ask --oneshot --verbose ">=app-crypt/mit-krb5-1.4.3-r3"
Threat Level: High
Click HERE for more information and discussions on this network vulnerability scan.
|