The newEntry function in ptserver/ptprocs.c in OpenAFS before 1.6.17 allows remote authenticated users from foreign Kerberos realms to bypass intended access restrictions and create arbitrary groups as administrators by leveraging mishandling of the creator ID.
References
Information
Published : 2016-05-13 09:59
Updated : 2016-05-19 09:43
NVD link : CVE-2016-2860
Mitre link : CVE-2016-2860
JSON object : View
CWE
CWE-284
Improper Access Control
Products Affected
debian
- debian_linux
openafs
- openafs