Kerberos 4 (aka krb4) allows local users to overwrite arbitrary files via a symlink attack on new ticket files.
Affected Software
| Name | Vendor | Start Version | End Version |
|---|
| Kerberos | Mit | 4 (including) | 4 (including) |
| Kerberos_5 | Mit | 1.5.2 (including) | 1.5.2 (including) |
References