CVE-2011-1526
published 2011-07-11CVE-2011-1526: ftpd.c in the GSS-API FTP daemon in MIT Kerberos Version 5 Applications (aka krb5-appl) 1.0.1 and earlier does not check the krb5_setegid return value, which…
PriorityP336medium6.5CVSS 2.0
AVNACLAuSCPIPAP
EPSS
3.94%
89.3th percentile
ftpd.c in the GSS-API FTP daemon in MIT Kerberos Version 5 Applications (aka krb5-appl) 1.0.1 and earlier does not check the krb5_setegid return value, which allows remote authenticated users to bypass intended group access restrictions, and create, overwrite, delete, or read files, via standard FTP commands, related to missing autoconf tests in a configure script.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| mit | krb5-appl | < 1.0.1 | 1.0.1 |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
| suse | linux_enterprise_desktop | — | — |
| suse | linux_enterprise_desktop | — | — |
| suse | linux_enterprise_server | — | — |
| suse | linux_enterprise_server | — | — |
| suse | linux_enterprise_software_development_kit | — | — |
| suse | linux_enterprise_software_development_kit | — | — |
CVSS provenance
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-qc9v-p4hp-c5fh: ftpd
ghsa_unreviewed·2022-05-13
CVE-2011-1526 [MEDIUM] CWE-269 GHSA-qc9v-p4hp-c5fh: ftpd
ftpd.c in the GSS-API FTP daemon in MIT Kerberos Version 5 Applications (aka krb5-appl) 1.0.1 and earlier does not check the krb5_setegid return value, which allows remote authenticated users to bypass intended group access restrictions, and create, overwrite, delete, or read files, via standard FTP commands, related to missing autoconf tests in a configure script.
Red Hat
krb5-appl: ftpd incorrect group privilege dropping (MITKRB5-SA-2011-005)
vendor_redhat·2011-07-05·CVSS 6.5
CVE-2011-1526 [MEDIUM] krb5-appl: ftpd incorrect group privilege dropping (MITKRB5-SA-2011-005)
krb5-appl: ftpd incorrect group privilege dropping (MITKRB5-SA-2011-005)
ftpd.c in the GSS-API FTP daemon in MIT Kerberos Version 5 Applications (aka krb5-appl) 1.0.1 and earlier does not check the krb5_setegid return value, which allows remote authenticated users to bypass intended group access restrictions, and create, overwrite, delete, or read files, via standard FTP commands, related to missing autoconf tests in a configure script.
It was found that ftpd, a Kerberos-aware FTP server, did not properly drop privileges. On Red Hat Enterprise Linux 5, the ftpd daemon did not check for the potential failure of the krb5_setegid() function call. On systems where the set real, set effective, or set saved group ID system calls might fail, a remote FTP user could use this flaw to gain unautho
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2011-1526 krb5, krb5-appl: ftpd incorrect group privilege dropping (MITKRB5-SA-2011-005) [fedora-all]
bugzilla·2011-07-05·CVSS 6.5
CVE-2011-1526 [MEDIUM] CVE-2011-1526 krb5, krb5-appl: ftpd incorrect group privilege dropping (MITKRB5-SA-2011-005) [fedora-all]
CVE-2011-1526 krb5, krb5-appl: ftpd incorrect group privilege dropping (MITKRB5-SA-2011-005) [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include the bug IDs of the
respective parent bugs filed against the "Security Response" product.
Please mention CVE ids in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=711419
Please no
Bugzilla
CVE-2009-5064 glibc: ldd unexpected code execution issue [rhel-6.2]
bugzilla·2011-06-14·CVSS 6.9
CVE-2009-5064 [MEDIUM] CVE-2009-5064 glibc: ldd unexpected code execution issue [rhel-6.2]
CVE-2009-5064 glibc: ldd unexpected code execution issue [rhel-6.2]
Don't include me in crap like that. There is no problem. This is people making crap up.
Discussion:
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.
For information on the advisory, and where to find the updated
files, follow the link below.
If the solution does not work for you, open a new bug report.
http://rhn.redhat.com/errata/RHSA-2011-1526.html
Bugzilla
CVE-2011-1526 krb5, krb5-appl: ftpd incorrect group privilege dropping (MITKRB5-SA-2011-005)
bugzilla·2011-06-07·CVSS 6.5
CVE-2011-1526 [MEDIUM] CVE-2011-1526 krb5, krb5-appl: ftpd incorrect group privilege dropping (MITKRB5-SA-2011-005)
CVE-2011-1526 krb5, krb5-appl: ftpd incorrect group privilege dropping (MITKRB5-SA-2011-005)
It was found that the kerberized FTP server did not properly check for the
failure to set its effective group identifier (GID). A remote, authenticated
FTP user could use this flaw to gain unauthorized read or write access to files
whose group owner was the initial effective GID of the FTP daemon process.
References:
[1] http://web.mit.edu/kerberos/advisories/MITKRB5-SA-2011-005.txt
(not public yet)
[2] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1526
Upstream patch:
[3] http://web.mit.edu/kerberos/advisories/2011-005-patch.txt
Acknowledgements:
Red Hat would like to thank the MIT Kerberos project for reporting this issue. Upstream acknowledges Tim Zingelman as the original reporter
http://lists.fedoraproject.org/pipermail/package-announce/2011-July/062681.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2011-July/062699.htmlhttp://lists.opensuse.org/opensuse-security-announce/2011-10/msg00009.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-01/msg00002.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-01/msg00004.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-01/msg00005.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-01/msg00010.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-01/msg00011.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-01/msg00014.htmlhttp://secunia.com/advisories/45145http://secunia.com/advisories/45157http://secunia.com/advisories/48101http://securityreason.com/securityalert/8301http://web.mit.edu/kerberos/advisories/MITKRB5-SA-2011-005.txthttp://www.debian.org/security/2011/dsa-2283http://www.mandriva.com/security/advisories?name=MDVSA-2011:117http://www.osvdb.org/73617http://www.redhat.com/support/errata/RHSA-2011-0920.htmlhttp://www.securityfocus.com/archive/1/518733/100/0/threadedhttp://www.securityfocus.com/bid/48571https://bugzilla.redhat.com/show_bug.cgi?id=711419https://exchange.xforce.ibmcloud.com/vulnerabilities/68398http://lists.fedoraproject.org/pipermail/package-announce/2011-July/062681.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2011-July/062699.htmlhttp://lists.opensuse.org/opensuse-security-announce/2011-10/msg00009.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-01/msg00002.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-01/msg00004.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-01/msg00005.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-01/msg00010.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-01/msg00011.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-01/msg00014.htmlhttp://secunia.com/advisories/45145http://secunia.com/advisories/45157http://secunia.com/advisories/48101http://securityreason.com/securityalert/8301http://web.mit.edu/kerberos/advisories/MITKRB5-SA-2011-005.txthttp://www.debian.org/security/2011/dsa-2283http://www.mandriva.com/security/advisories?name=MDVSA-2011:117http://www.osvdb.org/73617http://www.redhat.com/support/errata/RHSA-2011-0920.htmlhttp://www.securityfocus.com/archive/1/518733/100/0/threadedhttp://www.securityfocus.com/bid/48571https://bugzilla.redhat.com/show_bug.cgi?id=711419https://exchange.xforce.ibmcloud.com/vulnerabilities/68398
2011-07-11
Published