Vulnerability Note VU#401660
MIT Kerberos (krb5) ftpd and ksu do not properly validate seteuid() calls
Overview
Privilege escalation vulnerabilities in MIT krb5 ftpd and ksu may allow an authenticated attacker to execute arbitrary code.
Description
The MIT krb 5 ftpd and ksu programs contain multiple privilege escalation vulnerabilities. These vulnerabilities are dependent on the host operating system's implementation of the seteuid() system call and result when seteuid() can fail due to resource exhaustion while changing to an unprivileged user ID. Some implementations of seteuid() do not expose the vulnerability.
|
Impact
An authenticated attacker may be able to execute arbitrary code with root privileges. |
Solution
Upgrade
|
|
Systems Affected (Learn More)
| Vendor | Status | Date Notified | Date Updated |
|---|---|---|---|
| Gentoo Linux | Affected | 28 Jul 2006 | 24 Aug 2006 |
| Mandriva, Inc. | Affected | 28 Jul 2006 | 24 Aug 2006 |
| MIT Kerberos Development Team | Affected | 27 Jul 2006 | 08 Aug 2006 |
| Apple Computer, Inc. | Not Affected | 28 Jul 2006 | 18 Aug 2006 |
| AttachmateWRQ, Inc. | Not Affected | 28 Jul 2006 | 23 Aug 2006 |
| IBM Corporation | Not Affected | 28 Jul 2006 | 08 Aug 2006 |
| Juniper Networks, Inc. | Not Affected | 28 Jul 2006 | 08 Aug 2006 |
| Conectiva Inc. | Unknown | 28 Jul 2006 | 28 Jul 2006 |
| Cray Inc. | Unknown | 28 Jul 2006 | 28 Jul 2006 |
| CyberSafe, Inc. | Unknown | 28 Jul 2006 | 28 Jul 2006 |
| Debian GNU/Linux | Unknown | 28 Jul 2006 | 24 Aug 2006 |
| EMC, Inc. (formerly Data General Corporation) | Unknown | 28 Jul 2006 | 28 Jul 2006 |
| Engarde Secure Linux | Unknown | 28 Jul 2006 | 28 Jul 2006 |
| F5 Networks, Inc. | Unknown | 28 Jul 2006 | 28 Jul 2006 |
| Fedora Project | Unknown | 28 Jul 2006 | 28 Jul 2006 |
CVSS Metrics (Learn More)
| Group | Score | Vector |
|---|---|---|
| Base | N/A | N/A |
| Temporal | N/A | N/A |
| Environmental | N/A | N/A |
References
- http://www.kb.cert.org/vuls/id/580124
- http://web.mit.edu/Kerberos/advisories/MITKRB5-SA-2006-001-setuid.txt
Credit
Thanks to the MIT Kerberos Team for reporting this issue. The MIT Kerberos Team in turn thanks Michael Calmer and Marcus Meissner at SUSE and Shiva Persaud at IBM for providing information about AIX.
This document was written by Ryan Giobbi.
Other Information
- CVE IDs: CVE-2006-3084
- Date Public: 26 Jul 2006
- Date First Published: 15 Aug 2006
- Date Last Updated: 16 Aug 2006
- Severity Metric: 2.33
- Document Revision: 37
Feedback
If you have feedback, comments, or additional information about this vulnerability, please send us email.