VDB
CVE-2007-3149
CVE-2007-3149
PUBLISHED
CVSS 7.199999809265137 HIGH
sudo, when linked with MIT Kerberos 5 (krb5), does not properly check whether a user can currently authenticate to Kerberos, which allows local users to gain privileges, in a manner unintended by the sudo security model, via certain KRB5_ environment variable settings. NOTE: another researcher disputes this vulnerability, stating that the attacker must be "a user, who can already log into your system, and can already use sudo."
EPSS 0.05% · 15.7th percentile
Risk Scores
CVSS 2.0
7.199999809265137
EPSS Score
0.05%
15.7th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| mit | kerberos_5 | |
| n/a | n/a | n/a |
| todd_miller | sudo | * |
Timeline
- Jun 11, 2007 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 1, 2022 CVE Updated
- May 20, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 26, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 3, 2023 EPSS Score
References
- 26540 third-party-advisory
- 24368 vdb
- http://www.sudo.ws/cgi-bin/cvsweb/sudo/auth/kerb5.c url
- 20070607 MIT krb5: makes sudo authentication issue MUCH worse. mailing-list
- 20070607 Sudo: local root compromise with krb5 enabled mailing-list
- 20070607 Re: Sudo: local root compromise with krb5 enabled mailing-list
- https://nvd.nist.gov/vuln/detail/CVE-2007-3149 advisory