Beveiligingsadvies

CVE-2011-2709

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2012-06-21 15:00:00
Laatst bijgewerkt 2024-08-06 23:08:23
Toegewezen door redhat
CVSS-score geen score
Status PUBLISHED

Beschrijving

libgssapi and libgssglue before 0.4 do not properly check privileges, which allows local users to load untrusted configuration files and execute arbitrary code via the GSSAPI_MECH_CONF environment variable, as demonstrated using mount.nfs.