fedoraproject sssd CVE-2011-1758 is a vulnerability in Fedora Project Sssd
Published on May 26, 2011

The krb5_save_ccname_done function in providers/krb5/krb5_auth.c in System Security Services Daemon (SSSD) 1.5.x before 1.5.7, when automatic ticket renewal and offline authentication are configured, uses a pathname string as a password, which allows local users to bypass Kerberos authentication by listing the /tmp directory to obtain the pathname.

Vendor Advisory Vendor Advisory NVD


Products Associated with CVE-2011-1758

Want to know whenever a new CVE is published for Fedora Project Sssd? stack.watch will email you.

 

Exploit Probability

EPSS
0.05%
Percentile
14.66%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.