Title : Redhat Security Update Fixes pam_krb5 Privilege Escalation Issue VUPEN ID : VUPEN/ADV-2008-2720 CVE ID : CVE-2008-3825
Rated as : Moderate Risk
Remotely Exploitable : No Locally Exploitable : Yes Release Date : 2008-10-03
Technical Description
A vulnerability has been identified in various Redhat products, which could be exploited by malicious users to gain elevated privileges. This issue is caused by an error in the pam_krb5 module when configured to use an existing credential cache via the "existing_ticket" option, which could allow a local user to gain elevated privileges by using a different, local user's credential cache.