VDB
CERTCC-2000-602625
CERTCC-2000-602625
PUBLISHED
The environment variables krb4proxy and KRBCONFDIR may be respected by client programs such as login or su, in such a way that local or remote intruders can cause the client program to accept authentication requests from a malicious KDC. The vulnerabilites may be exploited remotely by passing these environment variables through a telnet connection.
Timeline
- Dec 9, 2000 CVE Published
- Jan 11, 2001 CVE Updated
- Mar 17, 2026 Security Advisory