Описание
Security update for sssd
This update for sssd fixes the following issues:
- CVE-2022-4254: Fixed a bug in libsss_certmap which could allow an attacker to gain control of the admin account and perform a full domain takeover. (bsc#1207474)
Список пакетов
SUSE Enterprise Storage 7.1
libipa_hbac-devel-1.16.1-150300.23.37.1
libipa_hbac0-1.16.1-150300.23.37.1
libsss_certmap-devel-1.16.1-150300.23.37.1
libsss_certmap0-1.16.1-150300.23.37.1
libsss_idmap-devel-1.16.1-150300.23.37.1
libsss_idmap0-1.16.1-150300.23.37.1
libsss_nss_idmap-devel-1.16.1-150300.23.37.1
libsss_nss_idmap0-1.16.1-150300.23.37.1
libsss_simpleifp-devel-1.16.1-150300.23.37.1
libsss_simpleifp0-1.16.1-150300.23.37.1
python3-sssd-config-1.16.1-150300.23.37.1
sssd-1.16.1-150300.23.37.1
sssd-ad-1.16.1-150300.23.37.1
sssd-common-1.16.1-150300.23.37.1
sssd-common-32bit-1.16.1-150300.23.37.1
sssd-dbus-1.16.1-150300.23.37.1
sssd-ipa-1.16.1-150300.23.37.1
sssd-krb5-1.16.1-150300.23.37.1
sssd-krb5-common-1.16.1-150300.23.37.1
sssd-ldap-1.16.1-150300.23.37.1
sssd-proxy-1.16.1-150300.23.37.1
sssd-tools-1.16.1-150300.23.37.1
sssd-winbind-idmap-1.16.1-150300.23.37.1
SUSE Linux Enterprise High Performance Computing 15 SP3-ESPOS
libipa_hbac-devel-1.16.1-150300.23.37.1
libipa_hbac0-1.16.1-150300.23.37.1
libsss_certmap-devel-1.16.1-150300.23.37.1
libsss_certmap0-1.16.1-150300.23.37.1
libsss_idmap-devel-1.16.1-150300.23.37.1
libsss_idmap0-1.16.1-150300.23.37.1
libsss_nss_idmap-devel-1.16.1-150300.23.37.1
libsss_nss_idmap0-1.16.1-150300.23.37.1
libsss_simpleifp-devel-1.16.1-150300.23.37.1
libsss_simpleifp0-1.16.1-150300.23.37.1
python3-sssd-config-1.16.1-150300.23.37.1
sssd-1.16.1-150300.23.37.1
sssd-ad-1.16.1-150300.23.37.1
sssd-common-1.16.1-150300.23.37.1
sssd-common-32bit-1.16.1-150300.23.37.1
sssd-dbus-1.16.1-150300.23.37.1
sssd-ipa-1.16.1-150300.23.37.1
sssd-krb5-1.16.1-150300.23.37.1
sssd-krb5-common-1.16.1-150300.23.37.1
sssd-ldap-1.16.1-150300.23.37.1
sssd-proxy-1.16.1-150300.23.37.1
sssd-tools-1.16.1-150300.23.37.1
sssd-winbind-idmap-1.16.1-150300.23.37.1
SUSE Linux Enterprise High Performance Computing 15 SP3-LTSS
libipa_hbac-devel-1.16.1-150300.23.37.1
libipa_hbac0-1.16.1-150300.23.37.1
libsss_certmap-devel-1.16.1-150300.23.37.1
libsss_certmap0-1.16.1-150300.23.37.1
libsss_idmap-devel-1.16.1-150300.23.37.1
libsss_idmap0-1.16.1-150300.23.37.1
libsss_nss_idmap-devel-1.16.1-150300.23.37.1
libsss_nss_idmap0-1.16.1-150300.23.37.1
libsss_simpleifp-devel-1.16.1-150300.23.37.1
libsss_simpleifp0-1.16.1-150300.23.37.1
python3-sssd-config-1.16.1-150300.23.37.1
sssd-1.16.1-150300.23.37.1
sssd-ad-1.16.1-150300.23.37.1
sssd-common-1.16.1-150300.23.37.1
sssd-common-32bit-1.16.1-150300.23.37.1
sssd-dbus-1.16.1-150300.23.37.1
sssd-ipa-1.16.1-150300.23.37.1
sssd-krb5-1.16.1-150300.23.37.1
sssd-krb5-common-1.16.1-150300.23.37.1
sssd-ldap-1.16.1-150300.23.37.1
sssd-proxy-1.16.1-150300.23.37.1
sssd-tools-1.16.1-150300.23.37.1
sssd-winbind-idmap-1.16.1-150300.23.37.1
SUSE Linux Enterprise Micro 5.1
libsss_certmap0-1.16.1-150300.23.37.1
libsss_idmap0-1.16.1-150300.23.37.1
libsss_nss_idmap0-1.16.1-150300.23.37.1
sssd-1.16.1-150300.23.37.1
sssd-common-1.16.1-150300.23.37.1
sssd-krb5-common-1.16.1-150300.23.37.1
sssd-ldap-1.16.1-150300.23.37.1
SUSE Linux Enterprise Micro 5.2
libsss_certmap0-1.16.1-150300.23.37.1
libsss_idmap0-1.16.1-150300.23.37.1
libsss_nss_idmap0-1.16.1-150300.23.37.1
sssd-1.16.1-150300.23.37.1
sssd-common-1.16.1-150300.23.37.1
sssd-krb5-common-1.16.1-150300.23.37.1
sssd-ldap-1.16.1-150300.23.37.1
SUSE Linux Enterprise Real Time 15 SP3
libipa_hbac-devel-1.16.1-150300.23.37.1
libipa_hbac0-1.16.1-150300.23.37.1
libsss_certmap-devel-1.16.1-150300.23.37.1
libsss_certmap0-1.16.1-150300.23.37.1
libsss_idmap-devel-1.16.1-150300.23.37.1
libsss_idmap0-1.16.1-150300.23.37.1
libsss_nss_idmap-devel-1.16.1-150300.23.37.1
libsss_nss_idmap0-1.16.1-150300.23.37.1
libsss_simpleifp-devel-1.16.1-150300.23.37.1
libsss_simpleifp0-1.16.1-150300.23.37.1
python3-sssd-config-1.16.1-150300.23.37.1
sssd-1.16.1-150300.23.37.1
sssd-ad-1.16.1-150300.23.37.1
sssd-common-1.16.1-150300.23.37.1
sssd-common-32bit-1.16.1-150300.23.37.1
sssd-dbus-1.16.1-150300.23.37.1
sssd-ipa-1.16.1-150300.23.37.1
sssd-krb5-1.16.1-150300.23.37.1
sssd-krb5-common-1.16.1-150300.23.37.1
sssd-ldap-1.16.1-150300.23.37.1
sssd-proxy-1.16.1-150300.23.37.1
sssd-tools-1.16.1-150300.23.37.1
sssd-winbind-idmap-1.16.1-150300.23.37.1
SUSE Linux Enterprise Server 15 SP3-LTSS
libipa_hbac-devel-1.16.1-150300.23.37.1
libipa_hbac0-1.16.1-150300.23.37.1
libsss_certmap-devel-1.16.1-150300.23.37.1
libsss_certmap0-1.16.1-150300.23.37.1
libsss_idmap-devel-1.16.1-150300.23.37.1
libsss_idmap0-1.16.1-150300.23.37.1
libsss_nss_idmap-devel-1.16.1-150300.23.37.1
libsss_nss_idmap0-1.16.1-150300.23.37.1
libsss_simpleifp-devel-1.16.1-150300.23.37.1
libsss_simpleifp0-1.16.1-150300.23.37.1
python3-sssd-config-1.16.1-150300.23.37.1
sssd-1.16.1-150300.23.37.1
sssd-ad-1.16.1-150300.23.37.1
sssd-common-1.16.1-150300.23.37.1
sssd-common-32bit-1.16.1-150300.23.37.1
sssd-dbus-1.16.1-150300.23.37.1
sssd-ipa-1.16.1-150300.23.37.1
sssd-krb5-1.16.1-150300.23.37.1
sssd-krb5-common-1.16.1-150300.23.37.1
sssd-ldap-1.16.1-150300.23.37.1
sssd-proxy-1.16.1-150300.23.37.1
sssd-tools-1.16.1-150300.23.37.1
sssd-winbind-idmap-1.16.1-150300.23.37.1
SUSE Linux Enterprise Server for SAP Applications 15 SP3
libipa_hbac-devel-1.16.1-150300.23.37.1
libipa_hbac0-1.16.1-150300.23.37.1
libsss_certmap-devel-1.16.1-150300.23.37.1
libsss_certmap0-1.16.1-150300.23.37.1
libsss_idmap-devel-1.16.1-150300.23.37.1
libsss_idmap0-1.16.1-150300.23.37.1
libsss_nss_idmap-devel-1.16.1-150300.23.37.1
libsss_nss_idmap0-1.16.1-150300.23.37.1
libsss_simpleifp-devel-1.16.1-150300.23.37.1
libsss_simpleifp0-1.16.1-150300.23.37.1
python3-sssd-config-1.16.1-150300.23.37.1
sssd-1.16.1-150300.23.37.1
sssd-ad-1.16.1-150300.23.37.1
sssd-common-1.16.1-150300.23.37.1
sssd-common-32bit-1.16.1-150300.23.37.1
sssd-dbus-1.16.1-150300.23.37.1
sssd-ipa-1.16.1-150300.23.37.1
sssd-krb5-1.16.1-150300.23.37.1
sssd-krb5-common-1.16.1-150300.23.37.1
sssd-ldap-1.16.1-150300.23.37.1
sssd-proxy-1.16.1-150300.23.37.1
sssd-tools-1.16.1-150300.23.37.1
sssd-winbind-idmap-1.16.1-150300.23.37.1
SUSE Manager Proxy 4.2
libipa_hbac-devel-1.16.1-150300.23.37.1
libipa_hbac0-1.16.1-150300.23.37.1
libsss_certmap-devel-1.16.1-150300.23.37.1
libsss_certmap0-1.16.1-150300.23.37.1
libsss_idmap-devel-1.16.1-150300.23.37.1
libsss_idmap0-1.16.1-150300.23.37.1
libsss_nss_idmap-devel-1.16.1-150300.23.37.1
libsss_nss_idmap0-1.16.1-150300.23.37.1
libsss_simpleifp-devel-1.16.1-150300.23.37.1
libsss_simpleifp0-1.16.1-150300.23.37.1
python3-sssd-config-1.16.1-150300.23.37.1
sssd-1.16.1-150300.23.37.1
sssd-ad-1.16.1-150300.23.37.1
sssd-common-1.16.1-150300.23.37.1
sssd-common-32bit-1.16.1-150300.23.37.1
sssd-dbus-1.16.1-150300.23.37.1
sssd-ipa-1.16.1-150300.23.37.1
sssd-krb5-1.16.1-150300.23.37.1
sssd-krb5-common-1.16.1-150300.23.37.1
sssd-ldap-1.16.1-150300.23.37.1
sssd-proxy-1.16.1-150300.23.37.1
sssd-tools-1.16.1-150300.23.37.1
sssd-winbind-idmap-1.16.1-150300.23.37.1
SUSE Manager Retail Branch Server 4.2
libipa_hbac-devel-1.16.1-150300.23.37.1
libipa_hbac0-1.16.1-150300.23.37.1
libsss_certmap-devel-1.16.1-150300.23.37.1
libsss_certmap0-1.16.1-150300.23.37.1
libsss_idmap-devel-1.16.1-150300.23.37.1
libsss_idmap0-1.16.1-150300.23.37.1
libsss_nss_idmap-devel-1.16.1-150300.23.37.1
libsss_nss_idmap0-1.16.1-150300.23.37.1
libsss_simpleifp-devel-1.16.1-150300.23.37.1
libsss_simpleifp0-1.16.1-150300.23.37.1
python3-sssd-config-1.16.1-150300.23.37.1
sssd-1.16.1-150300.23.37.1
sssd-ad-1.16.1-150300.23.37.1
sssd-common-1.16.1-150300.23.37.1
sssd-common-32bit-1.16.1-150300.23.37.1
sssd-dbus-1.16.1-150300.23.37.1
sssd-ipa-1.16.1-150300.23.37.1
sssd-krb5-1.16.1-150300.23.37.1
sssd-krb5-common-1.16.1-150300.23.37.1
sssd-ldap-1.16.1-150300.23.37.1
sssd-proxy-1.16.1-150300.23.37.1
sssd-tools-1.16.1-150300.23.37.1
sssd-winbind-idmap-1.16.1-150300.23.37.1
SUSE Manager Server 4.2
libipa_hbac-devel-1.16.1-150300.23.37.1
libipa_hbac0-1.16.1-150300.23.37.1
libsss_certmap-devel-1.16.1-150300.23.37.1
libsss_certmap0-1.16.1-150300.23.37.1
libsss_idmap-devel-1.16.1-150300.23.37.1
libsss_idmap0-1.16.1-150300.23.37.1
libsss_nss_idmap-devel-1.16.1-150300.23.37.1
libsss_nss_idmap0-1.16.1-150300.23.37.1
libsss_simpleifp-devel-1.16.1-150300.23.37.1
libsss_simpleifp0-1.16.1-150300.23.37.1
python3-sssd-config-1.16.1-150300.23.37.1
sssd-1.16.1-150300.23.37.1
sssd-ad-1.16.1-150300.23.37.1
sssd-common-1.16.1-150300.23.37.1
sssd-common-32bit-1.16.1-150300.23.37.1
sssd-dbus-1.16.1-150300.23.37.1
sssd-ipa-1.16.1-150300.23.37.1
sssd-krb5-1.16.1-150300.23.37.1
sssd-krb5-common-1.16.1-150300.23.37.1
sssd-ldap-1.16.1-150300.23.37.1
sssd-proxy-1.16.1-150300.23.37.1
sssd-tools-1.16.1-150300.23.37.1
sssd-winbind-idmap-1.16.1-150300.23.37.1
openSUSE Leap Micro 5.2
libsss_certmap0-1.16.1-150300.23.37.1
libsss_idmap0-1.16.1-150300.23.37.1
libsss_nss_idmap0-1.16.1-150300.23.37.1
sssd-1.16.1-150300.23.37.1
sssd-common-1.16.1-150300.23.37.1
sssd-krb5-common-1.16.1-150300.23.37.1
sssd-ldap-1.16.1-150300.23.37.1
Ссылки
- Link for SUSE-SU-2023:0204-1
- E-Mail link for SUSE-SU-2023:0204-1
- SUSE Security Ratings
- SUSE Bug 1207474
- SUSE CVE CVE-2022-4254 page
Описание
sssd: libsss_certmap fails to sanitise certificate data used in LDAP filters
Затронутые продукты
SUSE Enterprise Storage 7.1:libipa_hbac-devel-1.16.1-150300.23.37.1
SUSE Enterprise Storage 7.1:libipa_hbac0-1.16.1-150300.23.37.1
SUSE Enterprise Storage 7.1:libsss_certmap-devel-1.16.1-150300.23.37.1
SUSE Enterprise Storage 7.1:libsss_certmap0-1.16.1-150300.23.37.1
Ссылки
- CVE-2022-4254
- SUSE Bug 1207474