6.2
CVSSv2

CVE-2011-2709

Published: 21/06/2012 Updated: 02/03/2013
CVSS v2 Base Score: 6.2 | Impact Score: 10 | Exploitability Score: 1.9
VMScore: 552
Vector: AV:L/AC:H/Au:N/C:C/I:C/A:C

Vulnerability Summary

libgssapi and libgssglue prior to 0.4 do not properly check privileges, which allows local users to load untrusted configuration files and execute arbitrary code via the GSSAPI_MECH_CONF environment variable, as demonstrated using mount.nfs.

Vulnerable Product Search on Vulmon Subscribe to Product

umich libgssglue 0.2

umich libgssglue 0.1

umich libgssglue

umich libgssapi 0.2

umich libgssapi 0.1

umich libgssapi

Vendor Advisories

Debian Bug report logs - #670256 CVE-2011-2709: local root with newer nfs-client Package: libgssglue1; Maintainer for libgssglue1 is Anibal Monsalve Salazar <anibal@debianorg>; Source for libgssglue1 is src:libgssglue (PTS, buildd, popcon) Reported by: Florian Weimer <fw@denebenyode> Date: Tue, 24 Apr 2012 13:15:0 ...
Privilege escalation via the GSSAPI_MECH_CONF environment variable with setuid programs ...