GLSA Advocate
![Advocate Advocate](/images/ranks/rank-G-1-advocate.gif)
Joined: 12 May 2004 Posts: 2663
|
Posted: Wed Aug 23, 2006 8:26 pm Post subject: [ GLSA 200608-21 ] Heimdal: Multiple local privilege escalat |
|
|
Gentoo Linux Security Advisory
Title: Heimdal: Multiple local privilege escalation vulnerabilities (GLSA 200608-21)
Severity: high
Exploitable: local
Date: August 23, 2006
Bug(s): #143371
ID: 200608-21
Synopsis
Certain Heimdal components, ftpd and rcp, are vulnerable to a local privilege escalation.
Background
Heimdal is a free implementation of Kerberos 5.
Affected Packages
Package: app-crypt/heimdal
Vulnerable: < 0.7.2-r3
Unaffected: >= 0.7.2-r3
Architectures: All supported architectures
Description
The ftpd and rcp applications provided by Heimdal fail to check the return value of calls to seteuid().
Impact
A local attacker could exploit this vulnerability to execute arbitrary code with elevated privileges.
Workaround
There is no known workaround at this time.
Resolution
All Heimdal users should upgrade to the latest version: Code: | # emerge --sync
# emerge --ask --oneshot --verbose ">=app-crypt/heimdal-0.7.2-r3" |
References
Official advisory
CVE-2006-3083
CVE-2006-3084 |
|