CVE Vulnerabilities

CVE-2002-0754

Published: Aug 12, 2002 | Modified: Sep 05, 2008
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.2 HIGH
AV:L/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

Kerberos 5 su (k5su) in FreeBSD 4.4 and earlier relies on the getlogin system call to determine if the user running k5su is root, which could allow a root-initiated process to regain its privileges after it has dropped them.

Affected Software

Name Vendor Start Version End Version
Heimdal Freebsd 0.4e (including) 0.4e (including)
Heimdal Kth 0.4e (including) 0.4e (including)

References