CVE-2009-0361

UnknownEPSS 0.38%

Last modified

CVE-2009-0361 is a vulnerability of currently unknown severity. Russ Allbery pam-krb5 before 3.13, as used by libpam-heimdal, su in Solaris 10, and other software, does not properly handle calls to pam_setcred when running setuid, which allows local users to overwrite and change the ownership of arbitrary files by setting the KRB5CCNAME environment variable, and then launching a setuid application that performs certain pam_setcred operations.. EPSS estimates a 0.38% chance of exploitation in the next 30 days.

Description

Russ Allbery pam-krb5 before 3.13, as used by libpam-heimdal, su in Solaris 10, and other software, does not properly handle calls to pam_setcred when running setuid, which allows local users to overwrite and change the ownership of arbitrary files by setting the KRB5CCNAME environment variable, and then launching a setuid application that performs certain pam_setcred operations.

Metrics

EPSS Probability
0.38%

29.9th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
EyriePam-Krb5<= 3.12
EyriePam-Krb53.0
EyriePam-Krb53.1
EyriePam-Krb53.2
EyriePam-Krb53.3
EyriePam-Krb53.4
EyriePam-Krb53.5
EyriePam-Krb53.6
EyriePam-Krb53.7
EyriePam-Krb53.8
EyriePam-Krb53.9
EyriePam-Krb53.10
EyriePam-Krb53.11

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2009-0361?
Russ Allbery pam-krb5 before 3.13, as used by libpam-heimdal, su in Solaris 10, and other software, does not properly handle calls to pam_setcred when running setuid, which allows local users to overwrite and change the ownership of arbitrary files by setting the KRB5CCNAME environment variable, and then launching a setuid application that performs certain pam_setcred operations.
How severe is CVE-2009-0361?
Severity scoring for CVE-2009-0361 is pending analysis. The EPSS model estimates a 0.38% probability of exploitation in the next 30 days.
How do I fix CVE-2009-0361?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2009-0361?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST