Vulnerabilities > Umich

DATE CVE VULNERABILITY TITLE RISK
2012-06-21 CVE-2011-2709 Permissions, Privileges, and Access Controls vulnerability in Umich Libgssapi and Libgssglue
libgssapi and libgssglue before 0.4 do not properly check privileges, which allows local users to load untrusted configuration files and execute arbitrary code via the GSSAPI_MECH_CONF environment variable, as demonstrated using mount.nfs.
local
high complexity
umich CWE-264
6.2