CVE-2007-3149

Impact:
Important
Public Date:
2007-06-06
Bugzilla:
243702: CVE-2007-3149 Local authentication bypass in sudo

The MITRE CVE dictionary describes this issue as:

sudo, when linked with MIT Kerberos 5 (krb5), does not properly check whether a user can currently authenticate to Kerberos, which allows local users to gain privileges, in a manner unintended by the sudo security model, via certain KRB5_ environment variable settings. NOTE: another researcher disputes this vulnerability, stating that the attacker must be "a user, who can already log into your system, and can already use sudo."

Find out more about CVE-2007-3149 from the MITRE CVE dictionary dictionary and NIST NVD.

Statement

Not vulnerable. Versions of sudo package shipped with Red Hat Enterprise Linux versions 2.1, 3, 4 and 5 are linked with PAM support and never use libkrb5 authentication.

Last Modified

CVE description copyright © 2017, The MITRE Corporation

Close

Welcome! Check out the Getting Started with Red Hat page for quick tours and guides for common tasks.