CVE-2009-0361: Medium severity Eyrie Pam-krb5 vulnerability
Russ Allbery pam-krb5 before 3.13, as used by libpam-heimdal, su in Solaris 10, and other software, does not properly handle calls to pamsetcred when running setuid, which allows local users to overwrite and change the ownership of arbitrary files by setting the KRB5CCNAME environment variable, and then launching a setuid application that performs certain pamsetcred operations.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2009-0361?
CVE-2009-0361 is considered to have a medium severity due to its potential for local users to overwrite arbitrary files.
How do I fix CVE-2009-0361?
To fix CVE-2009-0361, upgrade the pam-krb5 module to version 3.13 or later.
Who is affected by CVE-2009-0361?
CVE-2009-0361 affects systems using pam-krb5 versions prior to 3.13, including various implementations like libpam-heimdal and Solaris 10.
What impact does CVE-2009-0361 have on system security?
CVE-2009-0361 allows local users to gain unauthorized access to and change ownership of files, posing a significant risk to system integrity.
Is there a specific configuration needed to mitigate CVE-2009-0361?
There is no specific configuration to mitigate CVE-2009-0361; the primary action is to apply the necessary software upgrades.