PT-2011-5244 · Mit+2 · Krb5-Plugin-Kdb-Ldap+10

Tim Zingelman

·

Published

1970-01-01

·

Updated

2021-02-02

·

CVE-2011-1526

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions krb5 versions 1.0.1 and earlier krb5-plugin-kdb-ldap (affected versions not specified) krb5-server (affected versions not specified) krb5-devel-32bit (affected versions not specified) krb5-devel (affected versions not specified) krb5 (affected versions not specified) krb5-32bit (affected versions not specified) krb5-plugin-preauth-pkinit (affected versions not specified) krb5-client (affected versions not specified)
Description The issue concerns multiple vulnerabilities in the krb5 package and its related components in the openSUSE operating system. These vulnerabilities can be exploited remotely, potentially leading to a disruption in the availability of protected information. The vulnerabilities may allow remote authenticated users to bypass intended group access restrictions, create, overwrite, delete, or read files via standard FTP commands. The exploitation can be carried out remotely.
Recommendations For krb5 versions 1.0.1 and earlier, update to a version later than 1.0.1 to resolve the issue. For krb5-plugin-kdb-ldap, krb5-server, krb5-devel-32bit, krb5-devel, krb5, krb5-32bit, krb5-plugin-preauth-pkinit, and krb5-client, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-05365
BDU:2015-05366
BDU:2015-05367
BDU:2015-05368
BDU:2015-05369
BDU:2015-05370
BDU:2015-05371
BDU:2015-05372
CVE-2011-1526
DSA-2283-1
RHSA-2011:0920
RHSA-2011_0920
RHSA-2012:0306
RHSA-2012_0306

Affected Products

Red Hat
Suse
Krb5
Krb5-32Bit
Krb5-Client
Krb5-Devel
Krb5-Devel-32Bit
Krb5-Plugin-Kdb-Ldap
Krb5-Plugin-Preauth-Pkinit
Krb5-Server
Opensuse