VDB

CERTCC-2000-602625

CERTCC-2000-602625 PUBLISHED

The environment variables krb4proxy and KRBCONFDIR may be respected by client programs such as login or su, in such a way that local or remote intruders can cause the client program to accept authentication requests from a malicious KDC. The vulnerabilites may be exploited remotely by passing these environment variables through a telnet connection.

Timeline

  • Dec 9, 2000 CVE Published
  • Jan 11, 2001 CVE Updated
  • Mar 17, 2026 Security Advisory
Open in Interactive Console →
$ Console Community · 100/wk Open console ›