Security Advisory

CVE-2011-2709

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2012-06-21 15:00:00
Last updated 2024-08-06 23:08:23
Assigner redhat
CVSS score not scored
State PUBLISHED

Description

libgssapi and libgssglue before 0.4 do not properly check privileges, which allows local users to load untrusted configuration files and execute arbitrary code via the GSSAPI_MECH_CONF environment variable, as demonstrated using mount.nfs.