Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2011-1758

Опубликовано: 26 мая 2011
Источник: nvd
CVSS2: 3.7
EPSS Низкий

Описание

The krb5_save_ccname_done function in providers/krb5/krb5_auth.c in System Security Services Daemon (SSSD) 1.5.x before 1.5.7, when automatic ticket renewal and offline authentication are configured, uses a pathname string as a password, which allows local users to bypass Kerberos authentication by listing the /tmp directory to obtain the pathname.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:fedoraproject:sssd:1.5.0:*:*:*:*:*:*:*
cpe:2.3:a:fedoraproject:sssd:1.5.1:*:*:*:*:*:*:*
cpe:2.3:a:fedoraproject:sssd:1.5.2:*:*:*:*:*:*:*
cpe:2.3:a:fedoraproject:sssd:1.5.3:*:*:*:*:*:*:*
cpe:2.3:a:fedoraproject:sssd:1.5.4:*:*:*:*:*:*:*
cpe:2.3:a:fedoraproject:sssd:1.5.5:*:*:*:*:*:*:*
cpe:2.3:a:fedoraproject:sssd:1.5.6:*:*:*:*:*:*:*
cpe:2.3:a:fedoraproject:sssd:1.5.6.1:*:*:*:*:*:*:*

EPSS

Процентиль: 15%
0.00048
Низкий

3.7 Low

CVSS2

Дефекты

CWE-287

Связанные уязвимости

ubuntu
больше 14 лет назад

The krb5_save_ccname_done function in providers/krb5/krb5_auth.c in System Security Services Daemon (SSSD) 1.5.x before 1.5.7, when automatic ticket renewal and offline authentication are configured, uses a pathname string as a password, which allows local users to bypass Kerberos authentication by listing the /tmp directory to obtain the pathname.

debian
больше 14 лет назад

The krb5_save_ccname_done function in providers/krb5/krb5_auth.c in Sy ...

github
больше 3 лет назад

The krb5_save_ccname_done function in providers/krb5/krb5_auth.c in System Security Services Daemon (SSSD) 1.5.x before 1.5.7, when automatic ticket renewal and offline authentication are configured, uses a pathname string as a password, which allows local users to bypass Kerberos authentication by listing the /tmp directory to obtain the pathname.

EPSS

Процентиль: 15%
0.00048
Низкий

3.7 Low

CVSS2

Дефекты

CWE-287