Heimdal: Multiple local privilege escalation vulnerabilities
1.
Gentoo Linux Security Advisory
Version Information
| Advisory Reference |
GLSA 200608-21 / Heimdal |
| Release Date |
August 23, 2006 |
| Latest Revision |
August 23, 2006: 01 |
| Impact |
high |
| Exploitable |
local |
| Package |
Vulnerable versions |
Unaffected versions |
Architecture(s) |
| app-crypt/heimdal |
<
0.7.2-r3 |
>=
0.7.2-r3 |
All supported architectures
|
Related bugreports:
#143371
Synopsis
Certain Heimdal components, ftpd and rcp, are vulnerable to a local
privilege escalation.
2.
Impact Information
Background
Heimdal is a free implementation of Kerberos 5.
Description
The ftpd and rcp applications provided by Heimdal fail to check the
return value of calls to seteuid().
Impact
A local attacker could exploit this vulnerability to execute arbitrary
code with elevated privileges.
3.
Resolution Information
Workaround
There is no known workaround at this time.
Resolution
All Heimdal users should upgrade to the latest version:
Code Listing 3.1: Resolution |
# emerge --sync
# emerge --ask --oneshot --verbose ">=app-crypt/heimdal-0.7.2-r3"
|
4.
References
|