The krb5_save_ccname_done function in providers/krb5/krb5_auth.c in System Security Services Daemon (SSSD) 1.5.x before 1.5.7, when automatic ticket renewal and offline authentication are configured, uses a pathname string as a password, which allows local users to bypass Kerberos authentication by listing the /tmp directory to obtain the pathname.
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Suse | — | Upgrade sssd-krb5-commonUpgrade sssd-wbclient-develUpgrade sssd-32bitUpgrade libsss_certmap0Upgrade sssd-ldapUpgrade libsss_idmap0Upgrade sssd-kcmUpgrade libsss_certmap-develUpgrade python3-sssd-configUpgrade sssd-ipaUpgrade libsss_nss_idmap-develUpgrade sssd-wbclientUpgrade libsss_idmap-develUpgrade python-sssd-configUpgrade libipa_hbac-develUpgrade python3-sss-murmurUpgrade libsss_simpleifp-develUpgrade libsss_sudo-develUpgrade libsss_sudoUpgrade sssd-dbusUpgrade libsss_nss_idmap0Upgrade libnfsidmap-sssUpgrade sssd-adUpgrade sssd-krb5Upgrade sssd-toolsUpgrade sssd-proxyUpgrade python3-sss_nss_idmapUpgrade python3-ipa_hbacUpgrade libsss_simpleifp0Upgrade sssdUpgrade libipa_hbac0Upgrade sssd-winbind-idmap | Aug 9, 2024 | Jun 28, 2013 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub