First published: Mon Aug 12 2002(Updated: )
Kerberos 5 su (k5su) in FreeBSD 4.5 and earlier does not verify that a user is a member of the wheel group before granting superuser privileges, which could allow unauthorized users to execute commands as root.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
FreeBSD Kernel | =4.5-release | |
FreeBSD Kernel | =4.4-release |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2002-0755 has a severity level that is considered critical due to the potential for unauthorized users to gain superuser privileges.
CVE-2002-0755 affects FreeBSD versions 4.4-release and 4.5-release.
To fix CVE-2002-0755, ensure that users are properly verified as members of the wheel group before granting superuser privileges.
CVE-2002-0755 can severely compromise system security by allowing unauthorized access to root privileges.
Administrators and users of FreeBSD versions 4.4 and 4.5 should be most concerned about CVE-2002-0755 due to the associated risks.