CVE Vulnerabilities

CVE-2011-2709

Published: Jun 21, 2012 | Modified: Mar 02, 2013
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.2 MEDIUM
AV:L/AC:H/Au:N/C:C/I:C/A:C
RedHat/V2
6.2 LOW
AV:L/AC:H/Au:N/C:C/I:C/A:C
RedHat/V3
Ubuntu
MEDIUM

libgssapi and libgssglue before 0.4 do not properly check privileges, which allows local users to load untrusted configuration files and execute arbitrary code via the GSSAPI_MECH_CONF environment variable, as demonstrated using mount.nfs.

Affected Software

Name Vendor Start Version End Version
Libgssglue Umich * 0.3 (including)
Libgssglue Umich 0.1 (including) 0.1 (including)
Libgssglue Umich 0.2 (including) 0.2 (including)
Libgssglue Ubuntu hardy *
Libgssglue Ubuntu lucid *
Libgssglue Ubuntu maverick *
Libgssglue Ubuntu natty *
Libgssglue Ubuntu oneiric *
Libgssglue Ubuntu precise *

References