Lucene search

K
cve[email protected]CVE-2007-3149
HistoryJun 11, 2007 - 6:30 p.m.

CVE-2007-3149

2007-06-1118:30:00
web.nvd.nist.gov
25
cve-2007-3149
sudo
mit kerberos 5
krb5
local privilege escalation

CVSS2

7.2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

AI Score

6.4

Confidence

High

EPSS

0

Percentile

5.1%

sudo, when linked with MIT Kerberos 5 (krb5), does not properly check whether a user can currently authenticate to Kerberos, which allows local users to gain privileges, in a manner unintended by the sudo security model, via certain KRB5_ environment variable settings. NOTE: another researcher disputes this vulnerability, stating that the attacker must be “a user, who can already log into your system, and can already use sudo.”

Affected configurations

NVD
Node
mitkerberos_5Match-
OR
todd_millersudoMatch1.6.8_p12
VendorProductVersionCPE
mitkerberos_5-cpe:/a:mit:kerberos_5:-:::
todd_millersudo1.6.8+p12cpe:/a:todd_miller:sudo:1.6.8+p12:::

CVSS2

7.2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

AI Score

6.4

Confidence

High

EPSS

0

Percentile

5.1%