KTH Kerberos 4 User-Supplied...

- AV AC AU C I A
发布: 2000-12-08
修订: 2025-04-13

Kerberos is a widely used network service authentication system. The version of Kerberos developed and maintained by KTH (Swedish Royal Institute of Technology) contains a vulnerability in its use of a user-supplied environment variable that may allow a malicious user with local access to elevate privileges. The environment variable, KRBCONFDIR, is used by Kerberos-enabled services to specify the directory in which KTH Kerberos 4 configuration files are located. For security reasons, this variable is not used when the authenticating process is setuid (the effective privileges do not match the real privileges) because the value is assumed to be user-definable. This is to prevent users from supplying malicious Kerberos config files. Unfortunately the method of checking the effective uid against the real uid is flawed in the case of telnet. When telnetting to a host, login is spawned with effective and real uid 0 privileges, making any such security check successful by default. It is...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息