Sploitus

CVE-2007-3149

No indexed exploits for CVE-2007-3149 yet

sudo, when linked with MIT Kerberos 5 (krb5), does not properly check whether a user can currently authenticate to Kerberos, which allows local users to gain privileges, in a manner unintended by the sudo security model, via certain KRB5_ environment variable settings. NOTE: another researcher disputes this vulnerability, stating that the attacker must be "a user, who can already log into your system, and can already use sudo."

Affected products
Alt Linux, Mit Kerberos 5, Sudo
Mit Kerberos 5
All versions
Todd Miller Sudo
= 1.6.8_p12
CVSS 2.0
7.2 HIGH
EPSS
0.4% (29th percentile)
NVD status
Modified
Published
2007-06-11
CVE-2007-3149 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2007-3149 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2007-3149 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.