Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-3811

Опубликовано: 04 дек. 2018
Источник: redhat
CVSS3: 4.1

Описание

A vulnerability was found in sssd. If a user was configured with no home directory set, sssd would return '/' (the root directory) instead of '' (the empty string / no home directory). This could impact services that restrict the user's filesystem access to within their home directory through chroot() etc. All versions before 2.1 are vulnerable.

A vulnerability was found in sssd where, if a user was configured with no home directory set, sssd would return '/' (the root directory) instead of '' (the empty string / no home directory). This could impact services that restrict the user's filesystem access to within their home directory through chroot().

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6sssdWill not fix
Red Hat Enterprise Linux 8sssdNot affected
Red Hat Enterprise Linux 7sssdFixedRHSA-2019:217706.08.2019

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-1188
https://bugzilla.redhat.com/show_bug.cgi?id=1656618sssd: fallback_homedir returns '/' for empty home directories in passwd file

4.1 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.2
ubuntu
больше 7 лет назад

A vulnerability was found in sssd. If a user was configured with no home directory set, sssd would return '/' (the root directory) instead of '' (the empty string / no home directory). This could impact services that restrict the user's filesystem access to within their home directory through chroot() etc. All versions before 2.1 are vulnerable.

CVSS3: 5.2
nvd
больше 7 лет назад

A vulnerability was found in sssd. If a user was configured with no home directory set, sssd would return '/' (the root directory) instead of '' (the empty string / no home directory). This could impact services that restrict the user's filesystem access to within their home directory through chroot() etc. All versions before 2.1 are vulnerable.

CVSS3: 5.2
debian
больше 7 лет назад

A vulnerability was found in sssd. If a user was configured with no ho ...

suse-cvrf
больше 7 лет назад

Recommended update for adcli, sssd

suse-cvrf
больше 7 лет назад

Security update for sssd

4.1 Medium

CVSS3