CVE-2011-1758
CVE-2011-1758 is a low-severity vulnerability in Fedoraproject Sssd with a CVSS 2.0 base score of 3.7. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-287.
Key facts
- Severity: Low (CVSS 2.0 base score 3.7)
- EPSS exploit prediction: 0% (27th percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-287
- Affected product: Fedoraproject Sssd
- Published:
- Last modified:
Description
The krb5_save_ccname_done function in providers/krb5/krb5_auth.c in System Security Services Daemon (SSSD) 1.5.x before 1.5.7, when automatic ticket renewal and offline authentication are configured, uses a pathname string as a password, which allows local users to bypass Kerberos authentication by listing the /tmp directory to obtain the pathname.
Frequently asked questions
- What is CVE-2011-1758?
- The krb5_save_ccname_done function in providers/krb5/krb5_auth.c in System Security Services Daemon (SSSD) 1.5.x before 1.5.7, when automatic ticket renewal and offline authentication are configured, uses a pathname string as a password, which allows local users to bypass Kerberos authentication by listing the /tmp directory to obtain the pathname.
- How severe is CVE-2011-1758?
- CVE-2011-1758 has a CVSS 2.0 base score of 3.7, rated low severity.
- Is CVE-2011-1758 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (27th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2011-1758?
- CVE-2011-1758 primarily affects Fedoraproject Sssd. In total, 8 product configurations (CPEs) are listed as vulnerable; see the affected-products list for the exact versions.
- How do I fix CVE-2011-1758?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- When was CVE-2011-1758 published?
- CVE-2011-1758 was published on 2011-05-26 and last updated on 2026-06-16.
References
- http://git.fedorahosted.org/git/?p=sssd.git%3Ba=commit%3Bh=fffdae81651b460f3d2c119c56d5caa09b4de42a
- http://lists.fedoraproject.org/pipermail/package-announce/2011-May/059532.html
- http://lists.fedoraproject.org/pipermail/package-announce/2011-May/059619.html
- http://openwall.com/lists/oss-security/2011/04/29/4
- https://bugzilla.redhat.com/show_bug.cgi?id=700867
- https://bugzilla.redhat.com/show_bug.cgi?id=700891
- https://fedorahosted.org/pipermail/sssd-devel/2011-April/006138.html
- https://fedorahosted.org/sssd/ticket/856
- https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.7
Affected products (8)
- cpe:2.3:a:fedoraproject:sssd:1.5.0:*:*:*:*:*:*:*
- cpe:2.3:a:fedoraproject:sssd:1.5.1:*:*:*:*:*:*:*
- cpe:2.3:a:fedoraproject:sssd:1.5.2:*:*:*:*:*:*:*
- cpe:2.3:a:fedoraproject:sssd:1.5.3:*:*:*:*:*:*:*
- cpe:2.3:a:fedoraproject:sssd:1.5.4:*:*:*:*:*:*:*
- cpe:2.3:a:fedoraproject:sssd:1.5.5:*:*:*:*:*:*:*
- cpe:2.3:a:fedoraproject:sssd:1.5.6:*:*:*:*:*:*:*
- cpe:2.3:a:fedoraproject:sssd:1.5.6.1:*:*:*:*:*:*:*
More vulnerabilities in Fedoraproject Sssd
- CVE-2022-4254 — High (CVSS 8.8): sssd: libsss_certmap fails to sanitise certificate data used in LDAP filters
- CVE-2021-3621 — High (CVSS 8.8): A flaw was found in SSSD, where the sssctl command was vulnerable to shell command injection via the logs-fetch and…
- CVE-2012-3462 — High (CVSS 8.8): A flaw was found in SSSD version 1.9.0. The SSSD's access-provider logic causes the result of the HBAC rule processing…
- CVE-2023-3758 — High (CVSS 7.1): A race condition flaw was found in sssd where the GPO policy is not consistently applied for authenticated users. This…
- CVE-2015-5292 — Medium (CVSS 6.8): Memory leak in the Privilege Attribute Certificate (PAC) responder plugin (sssd_pac_plugin.so) in System Security…
- CVE-2026-12610 — Medium (CVSS 6.4): A flaw was found in sssd. When authenticating with a YubiKey, the SSSD PAM responder can crash due to a use-after-free…
All CVEs affecting Fedoraproject Sssd →
Other CWE-287 (Improper Authentication) vulnerabilities
- CVE-2026-20317 — Critical (CVSS 10.0): As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Workload engineering…
- CVE-2026-19977 — Critical (CVSS 10.0): A vulnerability was detected in EFM ipTIME A3004T 14.19.0. The affected element is the function…
- CVE-2026-59500 — Critical (CVSS 10.0): CWE-287: Improper Authentication
- CVE-2024-27253 — Critical (CVSS 10.0): IBM DOORS Next 7.0.3 through 7.0.3 Interim Fix 018 could allow an authenticated user to bypass security logic to…
- CVE-2026-56162 — Critical (CVSS 10.0): Improper authentication in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network.
- CVE-2026-62825 — Critical (CVSS 10.0): Improper authentication in Azure Key Vault allows an unauthorized attacker to elevate privileges over a network.
Browse all CWE-287 (Improper Authentication) vulnerabilities →