CVE-2010-0014
Publication date 14 January 2010
Last updated 24 July 2024
Ubuntu priority
Description
System Security Services Daemon (SSSD) before 1.0.1, when the krb5 auth_provider is configured but the KDC is unreachable, allows physically proximate attackers to authenticate, via an arbitrary password, to the screen-locking program on a workstation that has any user’s Kerberos ticket-granting ticket (TGT); and might allow remote attackers to bypass intended access restrictions via vectors involving an arbitrary password in conjunction with a valid TGT.
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| sssd | 13.10 saucy |
Not affected
|
| 13.04 raring |
Not affected
|
|
| 12.10 quantal |
Not affected
|
|
| 12.04 LTS precise |
Not affected
|
|
| 11.10 oneiric |
Not affected
|
|
| 11.04 natty | Ignored end of life | |
| 10.10 maverick | Ignored end of life | |
| 10.04 LTS lucid | Ignored end of life | |
| 9.10 karmic | Ignored end of life | |
| 9.04 jaunty | Not in release | |
| 8.10 intrepid | Not in release | |
| 8.04 LTS hardy | Not in release | |
| 6.06 LTS dapper | Not in release |