CVE-2008-3825
Estado: ModificadaMedia (4.4)—
pam_krb5 2.2.14 de Red Hat Enterprise Linux (RHEL) 5 y versiones anteriores, cuando la opción existing_ticket está activa, utiliza privilegios incorrectos cuando lee una caché de credenciales Kerberos, lo cual permite a usuarios locales conseguir privilegios mediante el establecimiento de la variable de entorno KRB5CCNAME en un nombre de fichero cacheado de su elección y ejecutar los programas (1) su o (2) sudo. NOTA: puede haber un vector relacionado con la participación de sshd que tiene una importancia limitada.
CVSS
- Versión: 2.0
- Vector: AV:L/AC:M/Au:N/C:P/I:P/A:P
- Puntuación base: 4.4
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.35%
- Percentil entre todas las CVEs puntuadas: 27
- Fecha de la puntuación: 10/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (2)
CWE
- CWE-264
Referencias
- http://lists.opensuse.org/opensuse-security-announce/2008-12/msg00002.html
- http://secunia.com/advisories/32119
- http://secunia.com/advisories/32135
- http://secunia.com/advisories/32174
- http://secunia.com/advisories/43314
- http://www.mandriva.com/security/advisories?name=MDVSA-2008:209
- http://www.redhat.com/support/errata/RHSA-2008-0907.html
- http://www.securityfocus.com/archive/1/516397/100/0/threaded
- http://www.securityfocus.com/bid/31534
- http://www.securitytracker.com/id?1020978
- http://www.vmware.com/security/advisories/VMSA-2011-0003.html
- https://bugzilla.redhat.com/show_bug.cgi?id=461960
- https://exchange.xforce.ibmcloud.com/vulnerabilities/45635
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10923
- https://www.redhat.com/archives/fedora-package-announce/2008-October/msg00150.html
- https://www.redhat.com/archives/fedora-package-announce/2008-October/msg00166.html
- http://lists.opensuse.org/opensuse-security-announce/2008-12/msg00002.html
- http://secunia.com/advisories/32119
- http://secunia.com/advisories/32135
- http://secunia.com/advisories/32174
- http://secunia.com/advisories/43314
- http://www.mandriva.com/security/advisories?name=MDVSA-2008:209
- http://www.redhat.com/support/errata/RHSA-2008-0907.html
- http://www.securityfocus.com/archive/1/516397/100/0/threaded
- http://www.securityfocus.com/bid/31534
- http://www.securitytracker.com/id?1020978
- http://www.vmware.com/security/advisories/VMSA-2011-0003.html
- https://bugzilla.redhat.com/show_bug.cgi?id=461960
- https://exchange.xforce.ibmcloud.com/vulnerabilities/45635
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10923
- https://www.redhat.com/archives/fedora-package-announce/2008-October/msg00150.html
- https://www.redhat.com/archives/fedora-package-announce/2008-October/msg00166.html
JSON original (NVD)
Mostrar
{
"id": "CVE-2008-3825",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 4.4,
"accessVector": "LOCAL",
"vectorString": "AV:L/AC:M/Au:N/C:P/I:P/A:P",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "MEDIUM",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 6.4,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 3.4,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": true,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "secalert@redhat.com",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2008-10-03T15:07:10.777",
"references": [
{
"url": "http://lists.opensuse.org/opensuse-security-announce/2008-12/msg00002.html",
"source": "secalert@redhat.com"
},
{
"url": "http://secunia.com/advisories/32119",
"source": "secalert@redhat.com"
},
{
"url": "http://secunia.com/advisories/32135",
"source": "secalert@redhat.com"
},
{
"url": "http://secunia.com/advisories/32174",
"source": "secalert@redhat.com"
},
{
"url": "http://secunia.com/advisories/43314",
"source": "secalert@redhat.com"
},
{
"url": "http://www.mandriva.com/security/advisories?name=MDVSA-2008:209",
"source": "secalert@redhat.com"
},
{
"url": "http://www.redhat.com/support/errata/RHSA-2008-0907.html",
"source": "secalert@redhat.com"
},
{
"url": "http://www.securityfocus.com/archive/1/516397/100/0/threaded",
"source": "secalert@redhat.com"
},
{
"url": "http://www.securityfocus.com/bid/31534",
"source": "secalert@redhat.com"
},
{
"url": "http://www.securitytracker.com/id?1020978",
"source": "secalert@redhat.com"
},
{
"url": "http://www.vmware.com/security/advisories/VMSA-2011-0003.html",
"source": "secalert@redhat.com"
},
{
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=461960",
"source": "secalert@redhat.com"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/45635",
"source": "secalert@redhat.com"
},
{
"url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10923",
"source": "secalert@redhat.com"
},
{
"url": "https://www.redhat.com/archives/fedora-package-announce/2008-October/msg00150.html",
"source": "secalert@redhat.com"
},
{
"url": "https://www.redhat.com/archives/fedora-package-announce/2008-October/msg00166.html",
"source": "secalert@redhat.com"
},
{
"url": "http://lists.opensuse.org/opensuse-security-announce/2008-12/msg00002.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://secunia.com/advisories/32119",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://secunia.com/advisories/32135",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://secunia.com/advisories/32174",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://secunia.com/advisories/43314",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.mandriva.com/security/advisories?name=MDVSA-2008:209",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.redhat.com/support/errata/RHSA-2008-0907.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/archive/1/516397/100/0/threaded",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/31534",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securitytracker.com/id?1020978",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.vmware.com/security/advisories/VMSA-2011-0003.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=461960",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/45635",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10923",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.redhat.com/archives/fedora-package-announce/2008-October/msg00150.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.redhat.com/archives/fedora-package-announce/2008-October/msg00166.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-264"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "pam_krb5 2.2.14 in Red Hat Enterprise Linux (RHEL) 5 and earlier, when the existing_ticket option is enabled, uses incorrect privileges when reading a Kerberos credential cache, which allows local users to gain privileges by setting the KRB5CCNAME environment variable to an arbitrary cache filename and running the (1) su or (2) sudo program. NOTE: there may be a related vector involving sshd that has limited relevance."
},
{
"lang": "es",
"value": "pam_krb5 2.2.14 de Red Hat Enterprise Linux (RHEL) 5 y versiones anteriores, cuando la opción existing_ticket está activa, utiliza privilegios incorrectos cuando lee una caché de credenciales Kerberos, lo cual permite a usuarios locales conseguir privilegios mediante el establecimiento de la variable de entorno KRB5CCNAME en un nombre de fichero cacheado de su elección y ejecutar los programas (1) su o (2) sudo.\r\nNOTA: puede haber un vector relacionado con la participación de sshd que tiene una importancia limitada."
}
],
"lastModified": "2026-06-16T22:56:36.733",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:redhat:enterprise_linux:5:unknown:server:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "13A37367-3CF4-4568-8072-6D6A43A94508"
},
{
"criteria": "cpe:2.3:o:redhat:enterprise_linux_desktop:5:unknown:client:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "01FE5595-25D0-4D41-8A5F-8C1CB52CBAAC"
}
],
"operator": "OR"
}
]
}
],
"vendorComments": [
{
"comment": "This issue did not affect the version of pam_krb5 shipped in Red Hat Enterprise Linux 2.1, 3, or 4.",
"lastModified": "2017-09-28T21:31:52.727",
"organization": "Red Hat"
}
],
"sourceIdentifier": "secalert@redhat.com"
}