Ubuntu Security Notice USN-719-1 – It was discovered that pam_krb5 parsed environment variables when run with setuid applications. A local attacker could exploit this flaw to bypass authentication checks and gain root privileges. Derek Chan discovered that pam_krb5 incorrectly handled refreshing existing credentials when used with setuid applications. A local attacker could exploit this to create or overwrite arbitrary files, and possibly gain root privileges.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/74906/USN-719-1.txt
Source: https://packetstormsecurity.com/files/74906/Ubuntu-Security-Notice-719-1.html

