MIT Kerberos Development Team Information for VU#602625

KTH Kerberos environment variables krb4proxy and KRBCONFDIR may be used insecurely


Vendor Statement

I do not believe it is a problem. The krb4 code within the MIT krb5 distributions does not contain any setuid application code that calls the krb4 library. Certainly our telnetd does not permit those variables to be set.

