CVE-2011-2709: Medium severity umich libgssglue vulnerability
Published Jun 21, 2012
·Updated
libgssapi and libgssglue before 0.4 do not properly check privileges, which allows local users to load untrusted configuration files and execute arbitrary code via the GSSAPIMECHCONF environment variable, as demonstrated using mount.nfs.
Affected Software
6 affected components
Umich Libgssglue<=0.3
Umich Libgssglue=0.1
Umich Libgssglue=0.2
Umich Libgssapi=0.2
Umich Libgssapi<=0.3
Umich Libgssapi=0.1
Remediation
Event History
Jun 21, 2012
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2011-2709?
CVE-2011-2709 has a medium severity rating due to its potential to allow local users to execute arbitrary code.
2
How do I fix CVE-2011-2709?
To fix CVE-2011-2709, upgrade to libgssapi and libgssglue version 0.4 or later.
3
Which systems are affected by CVE-2011-2709?
CVE-2011-2709 affects versions of libgssapi and libgssglue prior to 0.4.
4
What type of attack does CVE-2011-2709 enable?
CVE-2011-2709 enables local users to load untrusted configuration files which can lead to arbitrary code execution.
5
Can CVE-2011-2709 be exploited remotely?
CVE-2011-2709 cannot be exploited remotely as it requires local user access to the affected system.