← back
CVE-2009-0360

CVE-2009-0360

23Vexday Risk Score

No sign of exploitation. It has a public proof of concept.

ssvc Attendepss 0.7%
from disclosure to weapon44 days
Published on NVDFeb 13
1st PoC+44d
exploitation probability
0.7%top 50% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
Russ Allbery pam-krb5 before 3.13, when linked against MIT Kerberos, does not properly initialize the Kerberos libraries for setuid use, which allows local users to gain privileges by pointing an environment variable to a modified Kerberos configuration file, and then launching a PAM-based setuid application.
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.