Jump to content

Advisories MDKSA-2006:139: Updated krb5 packages fix local privilege escalation vulnerability


paul
 Share

Recommended Posts

A flaw was discovered in some bundled Kerberos-aware packages that

would fail to check the results of the setuid() call. This call can

fail in some circumstances on the Linux 2.6 kernel if certain user

limits are reached, which could be abused by a local attacker to get

the applications to continue to run as root, possibly leading to an

elevation of privilege.

 

Updated packages have been patched to correct this issue.

Link to comment
Share on other sites

Guest
This topic is now closed to further replies.
 Share

×
×
  • Create New...