Oval Definition:oval:com.redhat.rhsa:def:20080907
Revision Date:2008-10-02Version:635
Title:RHSA-2008:0907: pam_krb5 security update (Moderate)
Description:The pam_krb5 module allows Pluggable Authentication Modules (PAM) aware applications to use Kerberos to verify user identities by obtaining user credentials at log in time.

  • A flaw was found in the pam_krb5 "existing_ticket" configuration option. If a system is configured to use an existing credential cache via the "existing_ticket" option, it may be possible for a local user to gain elevated privileges by using a different, local user's credential cache. (CVE-2008-3825)

    Red Hat would like to thank Stéphane Bertin for responsibly disclosing this issue.

    Users of pam_krb5 should upgrade to this updated package, which contains a backported patch to resolve this issue.
  • Family:unixClass:patch
    Status:Reference(s):CVE-2008-3825
    RHSA-2008:0907
    RHSA-2008:0907-01
    RHSA-2008:0907-01
    Platform(s):Red Hat Enterprise Linux 5
    Product(s):
    Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 5 is installed
  • AND pam_krb5 is earlier than 0:2.2.14-1.el5_2.1
  • AND pam_krb5 is signed with Red Hat redhatrelease2 key
  • BACK