PT-2011-5244 · Mit+2 · Krb5-Plugin-Kdb-Ldap+10
Tim Zingelman
·
Published
1970-01-01
·
Updated
2021-02-02
·
CVE-2011-1526
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
krb5 versions 1.0.1 and earlier
krb5-plugin-kdb-ldap (affected versions not specified)
krb5-server (affected versions not specified)
krb5-devel-32bit (affected versions not specified)
krb5-devel (affected versions not specified)
krb5 (affected versions not specified)
krb5-32bit (affected versions not specified)
krb5-plugin-preauth-pkinit (affected versions not specified)
krb5-client (affected versions not specified)
Description
The issue concerns multiple vulnerabilities in the krb5 package and its related components in the openSUSE operating system. These vulnerabilities can be exploited remotely, potentially leading to a disruption in the availability of protected information. The vulnerabilities may allow remote authenticated users to bypass intended group access restrictions, create, overwrite, delete, or read files via standard FTP commands. The exploitation can be carried out remotely.
Recommendations
For krb5 versions 1.0.1 and earlier, update to a version later than 1.0.1 to resolve the issue.
For krb5-plugin-kdb-ldap, krb5-server, krb5-devel-32bit, krb5-devel, krb5, krb5-32bit, krb5-plugin-preauth-pkinit, and krb5-client, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Red Hat
Suse
Krb5
Krb5-32Bit
Krb5-Client
Krb5-Devel
Krb5-Devel-32Bit
Krb5-Plugin-Kdb-Ldap
Krb5-Plugin-Preauth-Pkinit
Krb5-Server
Opensuse