CVE-2009-0361

Source
https://cve.org/CVERecord?id=CVE-2009-0361
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2009-0361.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2009-0361
Downstream
Published
2009-02-13T17:30:00Z
Modified
2026-04-10T03:40:36Z
Summary
[none]
Details

Russ Allbery pam-krb5 before 3.13, as used by libpam-heimdal, su in Solaris 10, and other software, does not properly handle calls to pam_setcred when running setuid, which allows local users to overwrite and change the ownership of arbitrary files by setting the KRB5CCNAME environment variable, and then launching a setuid application that performs certain pam_setcred operations.

References

Affected packages