CVE-2011-1758
26.05.2011, 18:55
The krb5_save_ccname_done function in providers/krb5/krb5_auth.c in System Security Services Daemon (SSSD) 1.5.x before 1.5.7, when automatic ticket renewal and offline authentication are configured, uses a pathname string as a password, which allows local users to bypass Kerberos authentication by listing the /tmp directory to obtain the pathname.Enginsight
Vendor | Product | Version |
---|---|---|
fedoraproject | sssd | 1.5.0 |
fedoraproject | sssd | 1.5.1 |
fedoraproject | sssd | 1.5.2 |
fedoraproject | sssd | 1.5.3 |
fedoraproject | sssd | 1.5.4 |
fedoraproject | sssd | 1.5.5 |
fedoraproject | sssd | 1.5.6 |
fedoraproject | sssd | 1.5.6.1 |
𝑥
= Vulnerable software versions

Ubuntu Releases
Common Weakness Enumeration
References