Bug 243702 (CVE-2007-3149) - CVE-2007-3149 Local authentication bypass in sudo
Summary: CVE-2007-3149 Local authentication bypass in sudo
Keywords:
Status: CLOSED NOTABUG
Alias: CVE-2007-3149
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
low
low
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL: http://www.securityfocus.com/archive/...
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2007-06-11 14:04 UTC by Lubomir Kundrak
Modified: 2021-11-12 19:41 UTC (History)
0 users

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Clone Of:
Environment:
Last Closed: 2007-06-12 08:42:09 UTC


Attachments (Terms of Use)

Description Lubomir Kundrak 2007-06-11 14:04:08 UTC
Description of problem:

Thor Lancelot Simon discovered a flaw in the way sudo handles krb5 
authentication that could be potentially exploited to gain elevated
privileges by bypassing a local authentication.

Comment 1 Lubomir Kundrak 2007-06-12 08:42:09 UTC
Official Statement from Red Hat (6/11/2007)
Not vulnerable. Versions of sudo package shipped with Red Hat Enterprise Linux
versions 2.1, 3, 4 and 5 are linked with PAM support and never use libkrb5
authentication.


Note You need to log in before you can comment on or make changes to this bug.