NVD

Id
8646  
Name
CVE-2011-1758  
Description
The krb5_save_ccname_done function in providers/krb5/krb5_auth.c in System Security Services Daemon (SSSD) 1.5.x before 1.5.7, when automatic ticket renewal and offline authentication are configured, uses a pathname string as a password, which allows local users to bypass Kerberos authentication by listing the /tmp directory to obtain the pathname.  
Reject
 
CVSS Version
2  
CVSS Score
3.7  
Severity
Low  
CVSS Base Score
3.7  
CVSS Impact Subscore
6.4  
CVSS Exploit Subscore
1.9  
CVSS Vector
(AV:L/AC:H/Au:N/C:P/I:P/A:P)  
Pub Date
2017-01-07  
Published
2011-05-26  
Modified Date
2011-05-27  
Seq
2011-1758  

Actions