Back to search
CVE-2011-2709
Published: Jun 21, 2012
Modified: Aug 6, 2024
PUBLISHED
Description
libgssapi and libgssglue before 0.4 do not properly check privileges, which allows local users to load untrusted configuration files and execute arbitrary code via the GSSAPI_MECH_CONF environment variable, as demonstrated using mount.nfs.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
https://bugzilla.novell.com/show_bug.cgi?id=694598
x_refsource_MISC
FEDORA-2012-7971
vendor-advisory
x_refsource_FEDORA
45075
third-party-advisory
x_refsource_SECUNIA
48490
vdb-entry
x_refsource_BID
FEDORA-2012-8067
vendor-advisory
x_refsource_FEDORA
50785
third-party-advisory
x_refsource_SECUNIA
50973
third-party-advisory
x_refsource_SECUNIA
SUSE-SU-2011:0696
vendor-advisory
x_refsource_SUSE
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now