PT-2011-3891 · Likewise · Lsass+1

Published

2011-07-27

·

Updated

2017-08-29

·

CVE-2011-2467

CVSS v2.0

5.8

Medium

VectorAV:A/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Lsass versions 5.4 through 6.1 Likewise Enterprise version 6.0
Description A SQL injection issue in lsassd in Lsass in the Likewise Security Authority allows local users to execute arbitrary SQL commands.
Recommendations For Lsass versions 5.4 through 6.1, consider restricting access to the SQL database to minimize the risk of exploitation. For Likewise Enterprise version 6.0, restrict access to the SQL database to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2011-2467

Affected Products

Likewise Enterprise
Lsass