Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

rocky логотип

RLSA-2021:3151

Опубликовано: 16 авг. 2021
Источник: rocky
Оценка: Important

Описание

Important: sssd security update

The System Security Services Daemon (SSSD) service provides a set of daemons to manage access to remote directories and authentication mechanisms. It also provides the Name Service Switch (NSS) and the Pluggable Authentication Modules (PAM) interfaces toward the system, and a pluggable back-end system to connect to multiple different account sources.

Security Fix(es):

  • sssd: shell command injection in sssctl (CVE-2021-3621)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Затронутые продукты

  • Rocky Linux 8

НаименованиеАрхитектураРелизRPM
libipa_hbaci6869.el8_4.2libipa_hbac-2.4.0-9.el8_4.2.i686.rpm
libsss_nss_idmapi6869.el8_4.2libsss_nss_idmap-2.4.0-9.el8_4.2.i686.rpm
libsss_nss_idmapx86_649.el8_4.2libsss_nss_idmap-2.4.0-9.el8_4.2.x86_64.rpm
libsss_simpleifpx86_649.el8_4.2libsss_simpleifp-2.4.0-9.el8_4.2.x86_64.rpm
python3-libipa_hbacx86_649.el8_4.2python3-libipa_hbac-2.4.0-9.el8_4.2.x86_64.rpm
sssd-krb5x86_649.el8_4.2sssd-krb5-2.4.0-9.el8_4.2.x86_64.rpm
sssdx86_649.el8_4.2sssd-2.4.0-9.el8_4.2.x86_64.rpm
libsss_idmapx86_649.el8_4.2libsss_idmap-2.4.0-9.el8_4.2.x86_64.rpm
sssd-clientx86_649.el8_4.2sssd-client-2.4.0-9.el8_4.2.x86_64.rpm
libipa_hbacx86_649.el8_4.2libipa_hbac-2.4.0-9.el8_4.2.x86_64.rpm

Показывать по

Связанные CVE

Исправления

Связанные уязвимости

CVSS3: 8.8
ubuntu
почти 4 года назад

A flaw was found in SSSD, where the sssctl command was vulnerable to shell command injection via the logs-fetch and cache-expire subcommands. This flaw allows an attacker to trick the root user into running a specially crafted sssctl command, such as via sudo, to gain root access. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.

CVSS3: 6.7
redhat
больше 4 лет назад

A flaw was found in SSSD, where the sssctl command was vulnerable to shell command injection via the logs-fetch and cache-expire subcommands. This flaw allows an attacker to trick the root user into running a specially crafted sssctl command, such as via sudo, to gain root access. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.

CVSS3: 8.8
nvd
почти 4 года назад

A flaw was found in SSSD, where the sssctl command was vulnerable to shell command injection via the logs-fetch and cache-expire subcommands. This flaw allows an attacker to trick the root user into running a specially crafted sssctl command, such as via sudo, to gain root access. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.

CVSS3: 8.8
debian
почти 4 года назад

A flaw was found in SSSD, where the sssctl command was vulnerable to s ...

suse-cvrf
больше 4 лет назад

Security update for sssd