CVE-2007-3149
sudo, when linked with MIT Kerberos 5 (krb5), does not properly check whether a user can currently authenticate to Kerberos, which allows local users to gain privileges, in a manner unintended by the sudo security model, via certain KRB5_ environment variable settings. NOTE: another researcher disputes this vulnerability, stating that the attacker must be "a user, who can already log into your system, and can already use sudo."
- Affected products
- Alt Linux, Mit Kerberos 5, Sudo
- Mit Kerberos 5
- All versions
- Todd Miller Sudo
- = 1.6.8_p12
- CVSS 2.0
- 7.2 HIGH
- EPSS
- 0.4% (29th percentile)
- NVD status
- Modified
- Published
- 2007-06-11
CVE-2007-3149 at NVD
No indexed exploits for CVE-2007-3149 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2007-3149 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.