PT-2010-1840 · Red Hat · Sssd

Stephen Gallagher

·

Publicado

2010-01-14

·

Atualizado

2010-01-15

·

CVE-2010-0014

CVSS v2.0

3.7

Baixa

VetorAV:L/AC:H/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions SSSD versions prior to 1.0.1
Description The issue allows physically proximate attackers to authenticate to the screen-locking program on a workstation using an arbitrary password when the Kerberos authentication provider is configured but the Key Distribution Center (KDC) is unreachable. This occurs if any user has a valid Kerberos ticket-granting ticket (TGT). Additionally, it might enable remote attackers to bypass intended access restrictions by using an arbitrary password in conjunction with a valid TGT.
Recommendations For versions prior to 1.0.1, update to version 1.0.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the screen-locking program or ensuring the KDC is always reachable when the krb5 auth provider is configured.

Correção

Improper Authentication

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2010-0014

Produtos afetados

Sssd