CVE-2011-2709
Severity CVSS v4.0:
Pending analysis
Type:
CWE-264
Permissions, Privileges, and Access Control
Publication date:
21/06/2012
Last modified:
02/03/2013
Description
libgssapi and libgssglue before 0.4 do not properly check privileges, which allows local users to load untrusted configuration files and execute arbitrary code via the GSSAPI_MECH_CONF environment variable, as demonstrated using mount.nfs.
Impact
Base Score 2.0
6.20
Severity 2.0
MEDIUM
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:umich:libgssglue:*:*:*:*:*:*:*:* | 0.3 (including) | |
cpe:2.3:a:umich:libgssglue:0.1:*:*:*:*:*:*:* | ||
cpe:2.3:a:umich:libgssglue:0.2:*:*:*:*:*:*:* | ||
cpe:2.3:a:umich:libgssapi:*:*:*:*:*:*:*:* | 0.3 (including) | |
cpe:2.3:a:umich:libgssapi:0.1:*:*:*:*:*:*:* | ||
cpe:2.3:a:umich:libgssapi:0.2:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://lists.fedoraproject.org/pipermail/package-announce/2012-June/082072.html
- http://lists.fedoraproject.org/pipermail/package-announce/2012-June/082297.html
- http://lwn.net/Alerts/449415/
- http://secunia.com/advisories/45075
- http://secunia.com/advisories/50785
- http://secunia.com/advisories/50973
- http://www.citi.umich.edu/projects/nfsv4/linux/libgssglue/libgssglue-0.4.tar.gz
- http://www.openwall.com/lists/oss-security/2011/07/21/3
- http://www.openwall.com/lists/oss-security/2011/07/22/4
- http://www.openwall.com/lists/oss-security/2011/08/12/10
- http://www.securityfocus.com/bid/48490
- https://bugzilla.novell.com/show_bug.cgi?id=694598