Feed/CVE-2011-1758
CVE-2011-1758LOWCVSS 3.7

CVE-2011-1758

Published May 26, 2011·Updated Jun 16, 2026

NVD Description

The krb5_save_ccname_done function in providers/krb5/krb5_auth.c in System Security Services Daemon (SSSD) 1.5.x before 1.5.7, when automatic ticket renewal and offline authentication are configured, uses a pathname string as a password, which allows local users to bypass Kerberos authentication by listing the /tmp directory to obtain the pathname.

CVSS Vector

AV:L/AC:H/Au:N/C:P/I:P/A:P

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free