New Search

KDM pam_setcred Privilege Escalation Vulnerability

oval:org.mitre.oval:def:193

KDM in KDE 3.1.3 and earlier does not verify whether the pam_setcred function call succeeds which may allow attackers to gain root privileges by triggering error conditions within PAM modules as demonstrated in certain configurations of the MIT pam_krb5 module.

Family:
unix
Status:
ACCEPTED
Platform(s):
  • Red Hat Linux 9
Class:
vulnerability
Reference(s):
  • CVE-2003-0690
Product(s):
  • KDM