CVE-2011-1758: Low severity fedora hosted sssd vulnerability

Published Apr 29, 2011
·
Updated

A flaw was introduced in SSSD 1.5.0 that, under certain conditions, would have sssd overwrite a cached password with the filename of the kerberos credential store (defined by krb5ccachetemplate in sssd.conf). This could allow an attacker to gain access to an account without knowing the password if they knew the cached-credential string.

This flaw does not affect earlier versions of SSSD that did not have support for automatic ticket renewal services.

Other sources

The krb5saveccnamedone function in providers/krb5/krb5auth.c in System Security Services Daemon (SSSD) 1.5.x before 1.5.7, when automatic ticket renewal and offline authentication are configured, uses a pathname string as a password, which allows local users to bypass Kerberos authentication by listing the /tmp directory to obtain the pathname.

MITRE

Affected Software

8 affected components
fedoraproject Sssd=1.5.2
fedoraproject Sssd=1.5.0
fedoraproject Sssd=1.5.5
fedoraproject Sssd=1.5.6.1
fedoraproject Sssd=1.5.3
fedoraproject Sssd=1.5.1
fedoraproject Sssd=1.5.6
fedoraproject Sssd=1.5.4

Event History

Apr 29, 2011
Data Sourced
04:23 PM
DescriptionSeverityAffected Software
May 26, 2011
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2011-1758?

CVE-2011-1758 is classified as a moderate severity vulnerability that could allow unauthorized access to accounts.

2

How do I fix CVE-2011-1758?

To fix CVE-2011-1758, upgrade SSSD to version 1.5.7 or later, where the vulnerability has been addressed.

3

Which versions of SSSD are affected by CVE-2011-1758?

CVE-2011-1758 affects SSSD versions 1.5.0 through 1.5.6.1 inclusive.

4

What condition leads to the vulnerability in CVE-2011-1758?

The vulnerability occurs when SSSD incorrectly overwrites a cached password with the filename of the Kerberos credential store.

5

Can CVE-2011-1758 be exploited remotely?

CVE-2011-1758 could potentially be exploited locally by an attacker with access to the system.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203