Rapid7 Vulnerability & Exploit Database

Gentoo Linux: CVE-2011-1526: MIT Kerberos 5 Applications: Multiple vulnerabilities

Back to Search

Gentoo Linux: CVE-2011-1526: MIT Kerberos 5 Applications: Multiple vulnerabilities

Severity
7
CVSS
(AV:N/AC:L/Au:S/C:P/I:P/A:P)
Published
07/11/2011
Created
07/25/2018
Added
10/30/2017
Modified
10/30/2017

Description

ftpd.c in the GSS-API FTP daemon in MIT Kerberos Version 5 Applications (aka krb5-appl) 1.0.1 and earlier does not check the krb5_setegid return value, which allows remote authenticated users to bypass intended group access restrictions, and create, overwrite, delete, or read files, via standard FTP commands, related to missing autoconf tests in a configure script.

Solution(s)

  • gentoo-linux-upgrade-app-crypt-mit-krb5-appl

With Rapid7 live dashboards, I have a clear view of all the assets on my network, which ones can be exploited, and what I need to do in order to reduce the risk in my environment in real-time. No other tool gives us that kind of value and insight.

– Scott Cheney, Manager of Information Security, Sierra View Medical Center

;