CVE Vulnerabilities

CVE-2011-1758

Improper Authentication

Published: May 26, 2011 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
3.7 LOW
AV:L/AC:H/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
HIGH
root.io logo minimus.io logo echo.ai logo

The krb5_save_ccname_done function in providers/krb5/krb5_auth.c in System Security Services Daemon (SSSD) 1.5.x before 1.5.7, when automatic ticket renewal and offline authentication are configured, uses a pathname string as a password, which allows local users to bypass Kerberos authentication by listing the /tmp directory to obtain the pathname.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

NameVendorStart VersionEnd Version
SssdFedoraproject1.5.0 (including)1.5.0 (including)
SssdFedoraproject1.5.1 (including)1.5.1 (including)
SssdFedoraproject1.5.2 (including)1.5.2 (including)
SssdFedoraproject1.5.3 (including)1.5.3 (including)
SssdFedoraproject1.5.4 (including)1.5.4 (including)
SssdFedoraproject1.5.5 (including)1.5.5 (including)
SssdFedoraproject1.5.6 (including)1.5.6 (including)
SssdFedoraproject1.5.6.1 (including)1.5.6.1 (including)
SssdUbuntuupstream*

Potential Mitigations

References