Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2023:0200-1

Опубликовано: 27 янв. 2023
Источник: suse-cvrf

Описание

Security update for sssd

This update for sssd fixes the following issues:

  • CVE-2022-4254: Fixed a bug in libsss_certmap which could allow an attacker to gain control of the admin account and perform a full domain takeover. (bsc#1207474)

Список пакетов

SUSE Linux Enterprise Server 12 SP4-LTSS
libipa_hbac0-1.16.1-4.43.1
libsss_certmap0-1.16.1-4.43.1
libsss_idmap-devel-1.16.1-4.43.1
libsss_idmap0-1.16.1-4.43.1
libsss_nss_idmap-devel-1.16.1-4.43.1
libsss_nss_idmap0-1.16.1-4.43.1
libsss_simpleifp0-1.16.1-4.43.1
python-sssd-config-1.16.1-4.43.1
sssd-1.16.1-4.43.1
sssd-32bit-1.16.1-4.43.1
sssd-ad-1.16.1-4.43.1
sssd-dbus-1.16.1-4.43.1
sssd-ipa-1.16.1-4.43.1
sssd-krb5-1.16.1-4.43.1
sssd-krb5-common-1.16.1-4.43.1
sssd-ldap-1.16.1-4.43.1
sssd-proxy-1.16.1-4.43.1
sssd-tools-1.16.1-4.43.1
SUSE Linux Enterprise Server for SAP Applications 12 SP4
libipa_hbac0-1.16.1-4.43.1
libsss_certmap0-1.16.1-4.43.1
libsss_idmap0-1.16.1-4.43.1
libsss_nss_idmap0-1.16.1-4.43.1
libsss_simpleifp0-1.16.1-4.43.1
python-sssd-config-1.16.1-4.43.1
sssd-1.16.1-4.43.1
sssd-32bit-1.16.1-4.43.1
sssd-ad-1.16.1-4.43.1
sssd-dbus-1.16.1-4.43.1
sssd-ipa-1.16.1-4.43.1
sssd-krb5-1.16.1-4.43.1
sssd-krb5-common-1.16.1-4.43.1
sssd-ldap-1.16.1-4.43.1
sssd-proxy-1.16.1-4.43.1
sssd-tools-1.16.1-4.43.1
SUSE OpenStack Cloud 9
libipa_hbac0-1.16.1-4.43.1
libsss_certmap0-1.16.1-4.43.1
libsss_idmap0-1.16.1-4.43.1
libsss_nss_idmap0-1.16.1-4.43.1
libsss_simpleifp0-1.16.1-4.43.1
python-sssd-config-1.16.1-4.43.1
sssd-1.16.1-4.43.1
sssd-32bit-1.16.1-4.43.1
sssd-ad-1.16.1-4.43.1
sssd-dbus-1.16.1-4.43.1
sssd-ipa-1.16.1-4.43.1
sssd-krb5-1.16.1-4.43.1
sssd-krb5-common-1.16.1-4.43.1
sssd-ldap-1.16.1-4.43.1
sssd-proxy-1.16.1-4.43.1
sssd-tools-1.16.1-4.43.1
SUSE OpenStack Cloud Crowbar 9
libipa_hbac0-1.16.1-4.43.1
libsss_certmap0-1.16.1-4.43.1
libsss_idmap0-1.16.1-4.43.1
libsss_nss_idmap0-1.16.1-4.43.1
libsss_simpleifp0-1.16.1-4.43.1
python-sssd-config-1.16.1-4.43.1
sssd-1.16.1-4.43.1
sssd-32bit-1.16.1-4.43.1
sssd-ad-1.16.1-4.43.1
sssd-dbus-1.16.1-4.43.1
sssd-ipa-1.16.1-4.43.1
sssd-krb5-1.16.1-4.43.1
sssd-krb5-common-1.16.1-4.43.1
sssd-ldap-1.16.1-4.43.1
sssd-proxy-1.16.1-4.43.1
sssd-tools-1.16.1-4.43.1

Описание

sssd: libsss_certmap fails to sanitise certificate data used in LDAP filters


Затронутые продукты
SUSE Linux Enterprise Server 12 SP4-LTSS:libipa_hbac0-1.16.1-4.43.1
SUSE Linux Enterprise Server 12 SP4-LTSS:libsss_certmap0-1.16.1-4.43.1
SUSE Linux Enterprise Server 12 SP4-LTSS:libsss_idmap-devel-1.16.1-4.43.1
SUSE Linux Enterprise Server 12 SP4-LTSS:libsss_idmap0-1.16.1-4.43.1

Ссылки