Your submission was sent successfully! Close

You have successfully unsubscribed! Close

Thank you for signing up for our newsletter!
In these regular emails you will find the latest updates about Ubuntu and upcoming events where you can meet our team.Close

CVE-2011-1758

Published: 26 May 2011

The krb5_save_ccname_done function in providers/krb5/krb5_auth.c in System Security Services Daemon (SSSD) 1.5.x before 1.5.7, when automatic ticket renewal and offline authentication are configured, uses a pathname string as a password, which allows local users to bypass Kerberos authentication by listing the /tmp directory to obtain the pathname.

Priority

High

Status

Package Release Status
sssd
Launchpad, Ubuntu, Debian
dapper Does not exist

hardy Does not exist

lucid Not vulnerable

maverick Not vulnerable

natty Not vulnerable
(1.2.1-4.1ubuntu3)
oneiric Not vulnerable
(1.5.8-0ubuntu2)
upstream
Released (1.5.7)