CVE-2011-1758

SSSD <1.5.7 - Info Disclosure

Title source: llm

Description

The krb5_save_ccname_done function in providers/krb5/krb5_auth.c in System Security Services Daemon (SSSD) 1.5.x before 1.5.7, when automatic ticket renewal and offline authentication are configured, uses a pathname string as a password, which allows local users to bypass Kerberos authentication by listing the /tmp directory to obtain the pathname.

Scores

EPSS 0.0005
EPSS Percentile 14.6%

Classification

CWE
CWE-287
Status draft

Affected Products (8)

fedoraproject/sssd
fedoraproject/sssd
fedoraproject/sssd
fedoraproject/sssd
fedoraproject/sssd
fedoraproject/sssd
fedoraproject/sssd
fedoraproject/sssd

Timeline

Published May 26, 2011
Tracked Since Feb 18, 2026