CVE-2011-1758 describes a Kerberos authentication bypass vulnerability in System Security Services Daemon (SSSD) versions 1.5.x prior to 1.5.7, specifically affecting Fedora Project SSSD. When automatic ticket renewal and offline authentication are enabled, the krb5_save_ccname_done function incorrectly uses a pathname as a password, allowing local attackers to bypass authentication by listing the /tmp directory. This vulnerability has a low CVSS score of 3.7 (AV:L/AC:H/Au:N/C:P/I:P/A:P), indicating a local attack vector with high access complexity and partial impact on confidentiality, integrity, and availability. There is no evidence of active exploitation, publicly available exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.5.0CPE matchmatch criteria | cpe:2.3:a:fedoraproject:sssd:1.5.0:*:*:*:*:*:*:* | ||
1.5.1CPE matchmatch criteria | cpe:2.3:a:fedoraproject:sssd:1.5.1:*:*:*:*:*:*:* | ||
1.5.2CPE matchmatch criteria | cpe:2.3:a:fedoraproject:sssd:1.5.2:*:*:*:*:*:*:* | ||
1.5.3CPE matchmatch criteria | cpe:2.3:a:fedoraproject:sssd:1.5.3:*:*:*:*:*:*:* | ||
1.5.4CPE matchmatch criteria | cpe:2.3:a:fedoraproject:sssd:1.5.4:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:H/Au:N/C:P/I:P/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.