CVE-2011-1758
Severity CVSS v4.0:
Pending analysis
Type:
CWE-287
Authentication Issues
Publication date:
26/05/2011
Last modified:
13/02/2023
Description
The krb5_save_ccname_done function in providers/krb5/krb5_auth.c in System Security Services Daemon (SSSD) 1.5.x before 1.5.7, when automatic ticket renewal and offline authentication are configured, uses a pathname string as a password, which allows local users to bypass Kerberos authentication by listing the /tmp directory to obtain the pathname.
Impact
Base Score 2.0
3.70
Severity 2.0
LOW
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:fedoraproject:sssd:1.5.0:*:*:*:*:*:*:* | ||
cpe:2.3:a:fedoraproject:sssd:1.5.1:*:*:*:*:*:*:* | ||
cpe:2.3:a:fedoraproject:sssd:1.5.2:*:*:*:*:*:*:* | ||
cpe:2.3:a:fedoraproject:sssd:1.5.3:*:*:*:*:*:*:* | ||
cpe:2.3:a:fedoraproject:sssd:1.5.4:*:*:*:*:*:*:* | ||
cpe:2.3:a:fedoraproject:sssd:1.5.5:*:*:*:*:*:*:* | ||
cpe:2.3:a:fedoraproject:sssd:1.5.6:*:*:*:*:*:*:* | ||
cpe:2.3:a:fedoraproject:sssd:1.5.6.1:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://git.fedorahosted.org/git/?p=sssd.git%3Ba%3Dcommit%3Bh%3Dfffdae81651b460f3d2c119c56d5caa09b4de42a
- http://lists.fedoraproject.org/pipermail/package-announce/2011-May/059532.html
- http://lists.fedoraproject.org/pipermail/package-announce/2011-May/059619.html
- http://openwall.com/lists/oss-security/2011/04/29/4
- https://bugzilla.redhat.com/show_bug.cgi?id=700867
- https://bugzilla.redhat.com/show_bug.cgi?id=700891
- https://fedorahosted.org/pipermail/sssd-devel/2011-April/006138.html
- https://fedorahosted.org/sssd/ticket/856
- https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.7