Required CVE Record Information
Description
KDM in KDE 3.1.3 and earlier does not verify whether the pam_setcred function call succeeds, which may allow attackers to gain root privileges by triggering error conditions within PAM modules, as demonstrated in certain configurations of the MIT pam_krb5 module.
References 13 Total
- distro.conectiva.com.br: CLA-2003:747 vendor-advisory
- oval.cisecurity.org: oval:org.mitre.oval:def:193 vdb-entrysignature
- marc.info: 20030916 [KDE SECURITY ADVISORY] KDM vulnerabilities mailing-list
- debian.org: DSA-443 vendor-advisory
- redhat.com: RHSA-2003:289 vendor-advisory
- http://cert.uni-stuttgart.de/archive/suse/security/2002/12/msg00101.html
- redhat.com: RHSA-2003:287 vendor-advisory
- redhat.com: RHSA-2003:270 vendor-advisory
- redhat.com: RHSA-2003:286 vendor-advisory
- debian.org: DSA-388 vendor-advisory
- mandriva.com: MDKSA-2003:091 vendor-advisory
- http://www.kde.org/info/security/advisory-20030916-1.txt
- redhat.com: RHSA-2003:288 vendor-advisory
Updated:
This container includes required additional information provided by the CVE Program for this vulnerability.
References 13 Total
- distro.conectiva.com.br: CLA-2003:747 vendor-advisoryx_transferred
- oval.cisecurity.org: oval:org.mitre.oval:def:193 vdb-entrysignaturex_transferred
- marc.info: 20030916 [KDE SECURITY ADVISORY] KDM vulnerabilities mailing-listx_transferred
- debian.org: DSA-443 vendor-advisoryx_transferred
- redhat.com: RHSA-2003:289 vendor-advisoryx_transferred
- http://cert.uni-stuttgart.de/archive/suse/security/2002/12/msg00101.html x_transferred
- redhat.com: RHSA-2003:287 vendor-advisoryx_transferred
- redhat.com: RHSA-2003:270 vendor-advisoryx_transferred
- redhat.com: RHSA-2003:286 vendor-advisoryx_transferred
- debian.org: DSA-388 vendor-advisoryx_transferred
- mandriva.com: MDKSA-2003:091 vendor-advisoryx_transferred
- http://www.kde.org/info/security/advisory-20030916-1.txt x_transferred
- redhat.com: RHSA-2003:288 vendor-advisoryx_transferred