CVE-2011-1758

EUVD-2011-1757
The krb5_save_ccname_done function in providers/krb5/krb5_auth.c in System Security Services Daemon (SSSD) 1.5.x before 1.5.7, when automatic ticket renewal and offline authentication are configured, uses a pathname string as a password, which allows local users to bypass Kerberos authentication by listing the /tmp directory to obtain the pathname.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
3.7 UNKNOWN
LOCAL
HIGH
AV:L/AC:H/Au:N/C:P/I:P/A:P
Base Score
CVSS 3.x
EPSS Score
Percentile: 14%
Affected Products (NVD)
VendorProductVersion
fedoraprojectsssd
1.5.0
fedoraprojectsssd
1.5.1
fedoraprojectsssd
1.5.2
fedoraprojectsssd
1.5.3
fedoraprojectsssd
1.5.4
fedoraprojectsssd
1.5.5
fedoraprojectsssd
1.5.6
fedoraprojectsssd
1.5.6.1
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
sssd
bookworm
2.8.2-4
fixed
bullseye
2.4.1-2
fixed
sid
2.9.5-3
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
sssd
dapper
dne
hardy
dne
lucid
not-affected
maverick
not-affected
natty
not-affected
oneiric
not-affected