CVE-2008-5690: Low severity Sun OpenSolaris vulnerability
The Kerberos credential renewal feature in Sun Solaris 8, 9, and 10, and OpenSolaris build snv01 through snv104, allows local users to cause a denial of service (authentication failure) via unspecified vectors related to incorrect cache file permissions, and lack of credential storage by the storecred function in pamkrb5.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2008-5690?
The severity of CVE-2008-5690 is classified as a denial of service vulnerability.
How do I fix CVE-2008-5690?
To mitigate CVE-2008-5690, ensure that the cache file permissions are correctly set to restrict access.
What versions of Solaris are affected by CVE-2008-5690?
CVE-2008-5690 affects Sun Solaris 8, 9, 10, and OpenSolaris builds from snv_01 through snv_104.
Can local users exploit CVE-2008-5690?
Yes, local users can exploit CVE-2008-5690 to cause authentication failures through improper cache file permissions.
Is there a workaround for CVE-2008-5690 until a fix is applied?
Implementing strict permission settings on credential cache files serves as a temporary workaround for CVE-2008-5690.