libgssapi and libgssglue before 0.4 do not properly check privileges, which allows local users to load untrusted configuration files and execute arbitrary code via the GSSAPI_MECH_CONF environment variable, as demonstrated using mount.nfs.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Libgssglue | Umich | * | 0.3 (including) |
Libgssglue | Umich | 0.1 (including) | 0.1 (including) |
Libgssglue | Umich | 0.2 (including) | 0.2 (including) |
Libgssglue | Ubuntu | hardy | * |
Libgssglue | Ubuntu | lucid | * |
Libgssglue | Ubuntu | maverick | * |
Libgssglue | Ubuntu | natty | * |
Libgssglue | Ubuntu | oneiric | * |
Libgssglue | Ubuntu | precise | * |