CVE Database
/

CVE-2010-0014

Back to search

CVE-2010-0014

Published: Jan 14, 2010

Modified: Sep 16, 2024

PUBLISHED

Description

System Security Services Daemon (SSSD) before 1.0.1, when the krb5 auth_provider is configured but the KDC is unreachable, allows physically proximate attackers to authenticate, via an arbitrary password, to the screen-locking program on a workstation that has any user's Kerberos ticket-granting ticket (TGT); and might allow remote attackers to bypass intended access restrictions via vectors involving an arbitrary password in conjunction with a valid TGT.

VendorProductVersions

n/a

n/a

affected
n/a

References

38160
third-party-advisory
x_refsource_SECUNIA
37747
vdb-entry
x_refsource_BID

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now