OSVDB ID: 27871

Title: MIT Kerberos 5 ftpd seteuid() Local Privilege Escalation

Info

Disclosure

Aug 08, 2006

Discovery

Unknown

Dates

Exploit

Unknown

Solution

Unknown

Description

MIT Kerberos 5 contains a flaw that may allow a malicious user to gain access to unauthorized privileges. The issue is triggered when the seteuid() call fails in the ftpd program. This flaw may lead to a loss of confidentiality and/or integrity.

Classification

Location: Local Access Required
Attack Type: Information Disclosure, Input Manipulation
Impact: Loss of Confidentiality, Loss of Integrity
Exploit: Exploit Unknown

Solution

Upgrade to version 1.4.4, 1.5.1 or higher, as it has been reported to fix this vulnerability. Additionally, the vendor has released a patch to address this issue, or users may opt to apply the following workaround: Disable the affected program by removing the SUID bit

Products

MIT

Kerberos 5

1.4.3
1.4.4
1.5
1.5.1

References

Credit

  • Marcus Meissner - meissnersuse.de -
  • Michael Calmer -


Direct URL: http://osvdb.org/27871