CVE-2011-1758

The krb5_save_ccname_done function in providers/krb5/krb5_auth.c in System Security Services Daemon (SSSD) 1.5.x before 1.5.7, when automatic ticket renewal and offline authentication are configured, uses a pathname string as a password, which allows local users to bypass Kerberos authentication by listing the /tmp directory to obtain the pathname.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
3.7 UNKNOWN
LOCAL
HIGH
AV:L/AC:H/Au:N/C:P/I:P/A:P
Base Score
CVSS 3.x
EPSS Score
Percentile: 15%
Affected Products (NVD)
VendorProductVersion
fedoraprojectsssd
1.5.0
fedoraprojectsssd
1.5.1
fedoraprojectsssd
1.5.2
fedoraprojectsssd
1.5.3
fedoraprojectsssd
1.5.4
fedoraprojectsssd
1.5.5
fedoraprojectsssd
1.5.6
fedoraprojectsssd
1.5.6.1
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
sssd
bookworm
2.8.2-4
fixed
bullseye
2.4.1-2
fixed
sid
2.9.5-3
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
sssd
dapper
dne
hardy
dne
lucid
not-affected
maverick
not-affected
natty
not-affected
oneiric
not-affected
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
libipa_hbac-devel
suse enterprise desktop 15
1.16.1-1.22
fixed
suse enterprise desktop 15 SP1
1.16.1-3.18.1
fixed
suse enterprise sap 15
1.16.1-1.22
fixed
suse enterprise sap 15 SP1
1.16.1-3.18.1
fixed
suse enterprise server 15
1.16.1-1.22
fixed
suse enterprise server 15 SP1
1.16.1-3.18.1
fixed
libipa_hbac0
suse enterprise desktop 15
1.16.1-1.22
fixed
suse enterprise desktop 15 SP1
1.16.1-3.18.1
fixed
suse enterprise sap 12 SP5
1.16.1-4.17.1
fixed
suse enterprise sap 15
1.16.1-1.22
fixed
suse enterprise sap 15 SP1
1.16.1-3.18.1
fixed
suse enterprise server 12 SP5
1.16.1-4.17.1
fixed
suse enterprise server 15
1.16.1-1.22
fixed
suse enterprise server 15 SP1
1.16.1-3.18.1
fixed
libsss_certmap-devel
suse enterprise desktop 15
1.16.1-1.22
fixed
suse enterprise desktop 15 SP1
1.16.1-3.18.1
fixed
suse enterprise sap 15
1.16.1-1.22
fixed
suse enterprise sap 15 SP1
1.16.1-3.18.1
fixed
suse enterprise server 15
1.16.1-1.22
fixed
suse enterprise server 15 SP1
1.16.1-3.18.1
fixed
libsss_certmap0
suse enterprise desktop 15
1.16.1-1.22
fixed
suse enterprise desktop 15 SP1
1.16.1-3.18.1
fixed
suse enterprise sap 12 SP5
1.16.1-4.17.1
fixed
suse enterprise sap 15
1.16.1-1.22
fixed
suse enterprise sap 15 SP1
1.16.1-3.18.1
fixed
suse enterprise server 12 SP5
1.16.1-4.17.1
fixed
suse enterprise server 15
1.16.1-1.22
fixed
suse enterprise server 15 SP1
1.16.1-3.18.1
fixed
libsss_idmap-devel
suse enterprise desktop 15
1.16.1-1.22
fixed
suse enterprise desktop 15 SP1
1.16.1-3.18.1
fixed
suse enterprise sap 15
1.16.1-1.22
fixed
suse enterprise sap 15 SP1
1.16.1-3.18.1
fixed
suse enterprise server 15
1.16.1-1.22
fixed
suse enterprise server 15 SP1
1.16.1-3.18.1
fixed
libsss_idmap0
suse enterprise desktop 15
1.16.1-1.22
fixed
suse enterprise desktop 15 SP1
1.16.1-3.18.1
fixed
suse enterprise sap 12 SP5
1.16.1-4.17.1
fixed
suse enterprise sap 15
1.16.1-1.22
fixed
suse enterprise sap 15 SP1
1.16.1-3.18.1
fixed
suse enterprise server 12 SP5
1.16.1-4.17.1
fixed
suse enterprise server 15
1.16.1-1.22
fixed
suse enterprise server 15 SP1
1.16.1-3.18.1
fixed
libsss_nss_idmap-devel
suse enterprise desktop 15
1.16.1-1.22
fixed
suse enterprise desktop 15 SP1
1.16.1-3.18.1
fixed
suse enterprise sap 15
1.16.1-1.22
fixed
suse enterprise sap 15 SP1
1.16.1-3.18.1
fixed
suse enterprise server 15
1.16.1-1.22
fixed
suse enterprise server 15 SP1
1.16.1-3.18.1
fixed
libsss_nss_idmap0
suse enterprise desktop 15
1.16.1-1.22
fixed
suse enterprise desktop 15 SP1
1.16.1-3.18.1
fixed
suse enterprise sap 12 SP5
1.16.1-4.17.1
fixed
suse enterprise sap 15
1.16.1-1.22
fixed
suse enterprise sap 15 SP1
1.16.1-3.18.1
fixed
suse enterprise server 12 SP5
1.16.1-4.17.1
fixed
suse enterprise server 15
1.16.1-1.22
fixed
suse enterprise server 15 SP1
1.16.1-3.18.1
fixed
libsss_simpleifp-devel
suse enterprise desktop 15
1.16.1-1.22
fixed
suse enterprise desktop 15 SP1
1.16.1-3.18.1
fixed
suse enterprise sap 15
1.16.1-1.22
fixed
suse enterprise sap 15 SP1
1.16.1-3.18.1
fixed
suse enterprise server 15
1.16.1-1.22
fixed
suse enterprise server 15 SP1
1.16.1-3.18.1
fixed
libsss_simpleifp0
suse enterprise desktop 15
1.16.1-1.22
fixed
suse enterprise desktop 15 SP1
1.16.1-3.18.1
fixed
suse enterprise sap 12 SP5
1.16.1-4.17.1
fixed
suse enterprise sap 15
1.16.1-1.22
fixed
suse enterprise sap 15 SP1
1.16.1-3.18.1
fixed
suse enterprise server 12 SP5
1.16.1-4.17.1
fixed
suse enterprise server 15
1.16.1-1.22
fixed
suse enterprise server 15 SP1
1.16.1-3.18.1
fixed
python-sssd-config
suse enterprise sap 12 SP5
1.16.1-4.17.1
fixed
suse enterprise server 12 SP5
1.16.1-4.17.1
fixed
python3-sssd-config
suse enterprise desktop 15
1.16.1-1.22
fixed
suse enterprise desktop 15 SP1
1.16.1-3.18.1
fixed
suse enterprise sap 15
1.16.1-1.22
fixed
suse enterprise sap 15 SP1
1.16.1-3.18.1
fixed
suse enterprise server 15
1.16.1-1.22
fixed
suse enterprise server 15 SP1
1.16.1-3.18.1
fixed
sssd
suse enterprise desktop 15
1.16.1-1.22
fixed
suse enterprise desktop 15 SP1
1.16.1-3.18.1
fixed
suse enterprise sap 12 SP5
1.16.1-4.17.1
fixed
suse enterprise sap 15
1.16.1-1.22
fixed
suse enterprise sap 15 SP1
1.16.1-3.18.1
fixed
suse enterprise server 12 SP5
1.16.1-4.17.1
fixed
suse enterprise server 15
1.16.1-1.22
fixed
suse enterprise server 15 SP1
1.16.1-3.18.1
fixed
sssd-32bit
suse enterprise desktop 15
1.16.1-1.22
fixed
suse enterprise desktop 15 SP1
1.16.1-3.18.1
fixed
suse enterprise sap 12 SP5
1.16.1-4.17.1
fixed
suse enterprise sap 15
1.16.1-1.22
fixed
suse enterprise sap 15 SP1
1.16.1-3.18.1
fixed
suse enterprise server 12 SP5
1.16.1-4.17.1
fixed
suse enterprise server 15
1.16.1-1.22
fixed
suse enterprise server 15 SP1
1.16.1-3.18.1
fixed
sssd-ad
suse enterprise desktop 15
1.16.1-1.22
fixed
suse enterprise desktop 15 SP1
1.16.1-3.18.1
fixed
suse enterprise sap 12 SP5
1.16.1-4.17.1
fixed
suse enterprise sap 15
1.16.1-1.22
fixed
suse enterprise sap 15 SP1
1.16.1-3.18.1
fixed
suse enterprise server 12 SP5
1.16.1-4.17.1
fixed
suse enterprise server 15
1.16.1-1.22
fixed
suse enterprise server 15 SP1
1.16.1-3.18.1
fixed
sssd-dbus
suse enterprise desktop 15 SP1
1.16.1-3.18.1
fixed
suse enterprise sap 15 SP1
1.16.1-3.18.1
fixed
suse enterprise server 15 SP1
1.16.1-3.18.1
fixed
sssd-ipa
suse enterprise desktop 15
1.16.1-1.22
fixed
suse enterprise desktop 15 SP1
1.16.1-3.18.1
fixed
suse enterprise sap 12 SP5
1.16.1-4.17.1
fixed
suse enterprise sap 15
1.16.1-1.22
fixed
suse enterprise sap 15 SP1
1.16.1-3.18.1
fixed
suse enterprise server 12 SP5
1.16.1-4.17.1
fixed
suse enterprise server 15
1.16.1-1.22
fixed
suse enterprise server 15 SP1
1.16.1-3.18.1
fixed
sssd-krb5
suse enterprise desktop 15
1.16.1-1.22
fixed
suse enterprise desktop 15 SP1
1.16.1-3.18.1
fixed
suse enterprise sap 12 SP5
1.16.1-4.17.1
fixed
suse enterprise sap 15
1.16.1-1.22
fixed
suse enterprise sap 15 SP1
1.16.1-3.18.1
fixed
suse enterprise server 12 SP5
1.16.1-4.17.1
fixed
suse enterprise server 15
1.16.1-1.22
fixed
suse enterprise server 15 SP1
1.16.1-3.18.1
fixed
sssd-krb5-common
suse enterprise desktop 15
1.16.1-1.22
fixed
suse enterprise desktop 15 SP1
1.16.1-3.18.1
fixed
suse enterprise sap 12 SP5
1.16.1-4.17.1
fixed
suse enterprise sap 15
1.16.1-1.22
fixed
suse enterprise sap 15 SP1
1.16.1-3.18.1
fixed
suse enterprise server 12 SP5
1.16.1-4.17.1
fixed
suse enterprise server 15
1.16.1-1.22
fixed
suse enterprise server 15 SP1
1.16.1-3.18.1
fixed
sssd-ldap
suse enterprise desktop 15
1.16.1-1.22
fixed
suse enterprise desktop 15 SP1
1.16.1-3.18.1
fixed
suse enterprise sap 12 SP5
1.16.1-4.17.1
fixed
suse enterprise sap 15
1.16.1-1.22
fixed
suse enterprise sap 15 SP1
1.16.1-3.18.1
fixed
suse enterprise server 12 SP5
1.16.1-4.17.1
fixed
suse enterprise server 15
1.16.1-1.22
fixed
suse enterprise server 15 SP1
1.16.1-3.18.1
fixed
sssd-proxy
suse enterprise desktop 15
1.16.1-1.22
fixed
suse enterprise desktop 15 SP1
1.16.1-3.18.1
fixed
suse enterprise sap 12 SP5
1.16.1-4.17.1
fixed
suse enterprise sap 15
1.16.1-1.22
fixed
suse enterprise sap 15 SP1
1.16.1-3.18.1
fixed
suse enterprise server 12 SP5
1.16.1-4.17.1
fixed
suse enterprise server 15
1.16.1-1.22
fixed
suse enterprise server 15 SP1
1.16.1-3.18.1
fixed
sssd-tools
suse enterprise desktop 15
1.16.1-1.22
fixed
suse enterprise desktop 15 SP1
1.16.1-3.18.1
fixed
suse enterprise sap 12 SP5
1.16.1-4.17.1
fixed
suse enterprise sap 15
1.16.1-1.22
fixed
suse enterprise sap 15 SP1
1.16.1-3.18.1
fixed
suse enterprise server 12 SP5
1.16.1-4.17.1
fixed
suse enterprise server 15
1.16.1-1.22
fixed
suse enterprise server 15 SP1
1.16.1-3.18.1
fixed
sssd-wbclient
suse enterprise desktop 15
1.16.1-1.22
fixed
suse enterprise desktop 15 SP1
1.16.1-3.18.1
fixed
suse enterprise sap 15
1.16.1-1.22
fixed
suse enterprise sap 15 SP1
1.16.1-3.18.1
fixed
suse enterprise server 15
1.16.1-1.22
fixed
suse enterprise server 15 SP1
1.16.1-3.18.1
fixed
sssd-wbclient-devel
suse enterprise desktop 15
1.16.1-1.22
fixed
suse enterprise desktop 15 SP1
1.16.1-3.18.1
fixed
suse enterprise sap 15
1.16.1-1.22
fixed
suse enterprise sap 15 SP1
1.16.1-3.18.1
fixed
suse enterprise server 15
1.16.1-1.22
fixed
suse enterprise server 15 SP1
1.16.1-3.18.1
fixed