CVE Vulnerabilities

CVE-2011-2709

Published: Jun 21, 2012 | Modified: Mar 02, 2013
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.2 MEDIUM
AV:L/AC:H/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

libgssapi and libgssglue before 0.4 do not properly check privileges, which allows local users to load untrusted configuration files and execute arbitrary code via the GSSAPI_MECH_CONF environment variable, as demonstrated using mount.nfs.

Affected Software

Name Vendor Start Version End Version
Libgssglue Umich * 0.3 (including)
Libgssglue Umich 0.1 (including) 0.1 (including)
Libgssglue Umich 0.2 (including) 0.2 (including)

References