CVE
- Id
- 3235
- CVE No.
- CVE-2001-0417
- Status
- Candidate
- Description
- Kerberos 4 (aka krb4) allows local users to overwrite arbitrary files via a symlink attack on new ticket files.
- Phase
- Proposed (20010524)
- Votes
- ACCEPT(3) Baker, Cole, Ziese | NOOP(1) Wall | REJECT(3) Christey, Frech, Oliver
- Comments
- Frech> DUPLICATE OF CVE-2001-0036: KTH Kerberos IV allows local users to | overwrite arbitrary files via a symlink attack on a ticket file. | Oliver> Appears to be a subset of CVE-2001-036. | Christey> Change description to point out that the Kerberos 5 package is | affected. | FREEBSD:FreeBSD-SA-01:25 | Also ensure that the other problems described in the FreeBSD | advisory have CANs/CVEs. | CHANGE> [Christey changed vote from NOOP to REJECT] | Christey> Agree that these are dupes. Since CVE-2001-0036 is already | an official CVE entry, this candidate will be rejected. | This CAN"s references will be added to CVE-2001-0036.