[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248268

 
 

909

 
 

195051

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

ALAS2-2018-1127 --- sssd, python-sss, libsss_autofs, python-libsss_nss_idmap, libsss_nss_idmap, libsss_sudo, libsss_certmap, libsss_idmap, libipa_hbac, python-libipa_hbac, python-sssdconfig

ID: oval:org.secpod.oval:def:1700110Date: (C)2018-12-24   (M)2023-12-20
Class: PATCHFamily: unix




The UNIX pipe which sudo uses to contact SSSD and read the available sudo rules from SSSD utilizes too broad of a set of permissions. Any user who can send a message using the same raw protocol that sudo and SSSD use can read the sudo rules available for any user.

Platform:
Amazon Linux 2
Product:
sssd
python-sss
libsss_autofs
python-libsss_nss_idmap
libsss_nss_idmap
libsss_sudo
libsss_certmap
libsss_idmap
libipa_hbac
python-libipa_hbac
python-sssdconfig
Reference:
ALAS2-2018-1127
CVE-2018-10852
CVE    1
CVE-2018-10852
CPE    3
cpe:/a:sssd:python-sss
cpe:/o:amazon:linux:2
cpe:/a:sssd:sssd

© SecPod Technologies