Mandriva Linux Security Advisory – Stéphane Bertin discovered a flaw in the pam_krb5 existing_ticket configuration option where, if enabled and using an existing credential cache, it was possible for a local user to gain elevated privileges by using a different, local user’s credential cache. The updated packages have been patched to prevent this issue.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/70640/MDVSA-2008-209.txt
Source: https://packetstormsecurity.com/files/70640/Mandriva-Linux-Security-Advisory-2008-209.html