CVE-2011-1758
Description
The krb5_save_ccname_done function in providers/krb5/krb5_auth.c in System Security Services Daemon (SSSD) 1.5.x before 1.5.7, when automatic ticket renewal and offline authentication are configured, uses a pathname string as a password, which allows local users to bypass Kerberos authentication by listing the /tmp directory to obtain the pathname.
Predictions
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
No mitigations published for this CVE yet.
The vendor-content worker queues fetches as references arrive (check back in a few minutes). Or โ if you've already worked around this in production โ publish your fix to the community-verified tier.
โ Propose a mitigation on Community โ Mitigations published via the community go through AI scoring + 2 human reviewers + 7-day silent objection window before landing here withsource_tier=community-verified.
OS impact
Debian Fixed 4 releases
| Version | Status | Fixed in |
|---|---|---|
| trixie | Fixed | 0 |
| sid | Fixed | 0 |
| bullseye | Fixed | 0 |
| bookworm | Fixed | 0 |
References
- http://git.fedorahosted.org/git/?p=sssd.git%3Ba=commit%3Bh=fffdae81651b460f3d2c119c56d5caa09b4de42a
- http://lists.fedoraproject.org/pipermail/package-announce/2011-May/059532.html
- http://lists.fedoraproject.org/pipermail/package-announce/2011-May/059619.html
- http://openwall.com/lists/oss-security/2011/04/29/4
- https://bugzilla.redhat.com/show_bug.cgi?id=700867
- https://bugzilla.redhat.com/show_bug.cgi?id=700891
- https://fedorahosted.org/pipermail/sssd-devel/2011-April/006138.html
- https://fedorahosted.org/sssd/ticket/856
- https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.7
- https://security-tracker.debian.org/tracker/CVE-2011-1758
CWEs
CWE-287
Community-verified mitigations for this CVE will appear above when contributors publish them.
Verify integrity in audit chain (admin only). AS-IS.