Описание
Security update for sssd
This update for sssd fixes the following issues:
Security issue fixed:
- CVE-2018-16838: Fixed an authentication bypass related to the Group Policy Objects implementation (bsc#1124194)
Non-security issues fixed:
- Missing GPOs directory could have led to login problems (bsc#1132879)
- Fix a crash by adding a netgroup counter to struct nss_enum_index (bsc#1132657)
- Allow defaults sudoRole without sudoUser attribute (bsc#1135247)
Список пакетов
SUSE Linux Enterprise Desktop 12 SP4
libipa_hbac0-1.16.1-4.12.2
libsss_certmap0-1.16.1-4.12.2
libsss_idmap0-1.16.1-4.12.2
libsss_nss_idmap0-1.16.1-4.12.2
libsss_simpleifp0-1.16.1-4.12.2
python-sssd-config-1.16.1-4.12.2
sssd-1.16.1-4.12.2
sssd-32bit-1.16.1-4.12.2
sssd-ad-1.16.1-4.12.2
sssd-ipa-1.16.1-4.12.2
sssd-krb5-1.16.1-4.12.2
sssd-krb5-common-1.16.1-4.12.2
sssd-ldap-1.16.1-4.12.2
sssd-proxy-1.16.1-4.12.2
sssd-tools-1.16.1-4.12.2
SUSE Linux Enterprise Server 12 SP4
libipa_hbac0-1.16.1-4.12.2
libsss_certmap0-1.16.1-4.12.2
libsss_idmap0-1.16.1-4.12.2
libsss_nss_idmap0-1.16.1-4.12.2
libsss_simpleifp0-1.16.1-4.12.2
python-sssd-config-1.16.1-4.12.2
sssd-1.16.1-4.12.2
sssd-32bit-1.16.1-4.12.2
sssd-ad-1.16.1-4.12.2
sssd-ipa-1.16.1-4.12.2
sssd-krb5-1.16.1-4.12.2
sssd-krb5-common-1.16.1-4.12.2
sssd-ldap-1.16.1-4.12.2
sssd-proxy-1.16.1-4.12.2
sssd-tools-1.16.1-4.12.2
SUSE Linux Enterprise Server for SAP Applications 12 SP4
libipa_hbac0-1.16.1-4.12.2
libsss_certmap0-1.16.1-4.12.2
libsss_idmap0-1.16.1-4.12.2
libsss_nss_idmap0-1.16.1-4.12.2
libsss_simpleifp0-1.16.1-4.12.2
python-sssd-config-1.16.1-4.12.2
sssd-1.16.1-4.12.2
sssd-32bit-1.16.1-4.12.2
sssd-ad-1.16.1-4.12.2
sssd-ipa-1.16.1-4.12.2
sssd-krb5-1.16.1-4.12.2
sssd-krb5-common-1.16.1-4.12.2
sssd-ldap-1.16.1-4.12.2
sssd-proxy-1.16.1-4.12.2
sssd-tools-1.16.1-4.12.2
SUSE Linux Enterprise Software Development Kit 12 SP4
libipa_hbac-devel-1.16.1-4.12.2
libsss_idmap-devel-1.16.1-4.12.2
libsss_nss_idmap-devel-1.16.1-4.12.2
Ссылки
- Link for SUSE-SU-2019:1480-1
- E-Mail link for SUSE-SU-2019:1480-1
- SUSE Security Ratings
- SUSE Bug 1124194
- SUSE Bug 1132657
- SUSE Bug 1132879
- SUSE Bug 1135247
- SUSE CVE CVE-2018-16838 page
Описание
A flaw was found in sssd Group Policy Objects implementation. When the GPO is not readable by SSSD due to a too strict permission settings on the server side, SSSD will allow all authenticated users to login instead of denying access.
Затронутые продукты
SUSE Linux Enterprise Desktop 12 SP4:libipa_hbac0-1.16.1-4.12.2
SUSE Linux Enterprise Desktop 12 SP4:libsss_certmap0-1.16.1-4.12.2
SUSE Linux Enterprise Desktop 12 SP4:libsss_idmap0-1.16.1-4.12.2
SUSE Linux Enterprise Desktop 12 SP4:libsss_nss_idmap0-1.16.1-4.12.2
Ссылки
- CVE-2018-16838
- SUSE Bug 1124194