Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-3811

Опубликовано: 04 дек. 2018
Источник: redhat
CVSS3: 4.1
EPSS Низкий

Описание

A vulnerability was found in sssd. If a user was configured with no home directory set, sssd would return '/' (the root directory) instead of '' (the empty string / no home directory). This could impact services that restrict the user's filesystem access to within their home directory through chroot() etc. All versions before 2.1 are vulnerable.

A vulnerability was found in sssd where, if a user was configured with no home directory set, sssd would return '/' (the root directory) instead of '' (the empty string / no home directory). This could impact services that restrict the user's filesystem access to within their home directory through chroot().

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6sssdWill not fix
Red Hat Enterprise Linux 8sssdNot affected
Red Hat Enterprise Linux 7sssdFixedRHSA-2019:217706.08.2019

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-552->CWE-200
https://bugzilla.redhat.com/show_bug.cgi?id=1656618sssd: fallback_homedir returns '/' for empty home directories in passwd file

EPSS

Процентиль: 36%
0.00153
Низкий

4.1 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.2
ubuntu
около 7 лет назад

A vulnerability was found in sssd. If a user was configured with no home directory set, sssd would return '/' (the root directory) instead of '' (the empty string / no home directory). This could impact services that restrict the user's filesystem access to within their home directory through chroot() etc. All versions before 2.1 are vulnerable.

CVSS3: 5.2
nvd
около 7 лет назад

A vulnerability was found in sssd. If a user was configured with no home directory set, sssd would return '/' (the root directory) instead of '' (the empty string / no home directory). This could impact services that restrict the user's filesystem access to within their home directory through chroot() etc. All versions before 2.1 are vulnerable.

CVSS3: 5.2
debian
около 7 лет назад

A vulnerability was found in sssd. If a user was configured with no ho ...

suse-cvrf
почти 7 лет назад

Recommended update for adcli, sssd

suse-cvrf
почти 7 лет назад

Security update for sssd

EPSS

Процентиль: 36%
0.00153
Низкий

4.1 Medium

CVSS3