CVE-2011-1758

The krb5_save_ccname_done function in providers/krb5/krb5_auth.c in System Security Services Daemon (SSSD) 1.5.x before 1.5.7, when automatic ticket renewal and offline authentication are configured, uses a pathname string as a password, which allows local users to bypass Kerberos authentication by listing the /tmp directory to obtain the pathname.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
3.7 UNKNOWN
LOCAL
HIGH
AV:L/AC:H/Au:N/C:P/I:P/A:P
redhatCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 14%
VendorProductVersion
fedoraprojectsssd
1.5.0
fedoraprojectsssd
1.5.1
fedoraprojectsssd
1.5.2
fedoraprojectsssd
1.5.3
fedoraprojectsssd
1.5.4
fedoraprojectsssd
1.5.5
fedoraprojectsssd
1.5.6
fedoraprojectsssd
1.5.6.1
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
sssd
bullseye
2.4.1-2
fixed
bookworm
2.8.2-4
fixed
sid
2.9.5-3
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
sssd
oneiric
not-affected
natty
not-affected
maverick
not-affected
lucid
not-affected
hardy
dne
dapper
dne