NVD

Id
47692  
Name
CVE-2009-0360  
Description
Russ Allbery pam-krb5 before 3.13, when linked against MIT Kerberos, does not properly initialize the Kerberos libraries for setuid use, which allows local users to gain privileges by pointing an environment variable to a modified Kerberos configuration file, and then launching a PAM-based setuid application.  
Reject
 
CVSS Version
2  
CVSS Score
6.2  
Severity
Medium  
CVSS Base Score
6.2  
CVSS Impact Subscore
10  
CVSS Exploit Subscore
1.9  
CVSS Vector
(AV:L/AC:H/Au:N/C:C/I:C/A:C)  
Pub Date
2017-01-07  
Published
2009-02-13  
Modified Date
2011-03-07  
Seq
2009-0360  

Actions