suse · CVE-2011-1758

Quick triage

Priority: medium Published: 2021-05-30 12:57:23 UTC Updated: 2026-04-18 20:01:59 UTC

View at Official suse advisory, NVD, CVE.org · CVE detail

Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.

Tracker summary

CVE-2011-1758 severity moderate: SUSE including 235 source package names (libipa_hbac-devel-1.11.5.1-14.1, libipa_hbac-devel-1.11.5.1-5.20, …), 345 product×package rows across 30 product lines (SUSE Linux Enterprise Desktop 12, SUSE Linux Enterprise Desktop 12 SP1, … (30 product lines)): Fixed 345.

Description:

The krb5_save_ccname_done function in providers/krb5/krb5_auth.c in System Security Services Daemon (SSSD) 1.5.x before 1.5.7, when automatic ticket renewal and offline authentication are configured, uses a pathname string as a password, which allows local users to bypass Kerberos authentication by listing the /tmp directory to obtain the pathname.

cvelogic Threat Intelligence