Описание
Security update for sssd
This update for sssd fixes the following issues:
Security fixes:
- CVE-2023-3758: Fixed race condition during authorization that lead to GPO policies functioning inconsistently (bsc#1223100)
Other fixes:
- Extend sssctl command line tool to manage the cached GPOs (jsc#PED-7677)
- SSSD GPO host entries are ignored if computer cn does not match it's samaccountname (jsc#SLE-9298) (bsc#1160688)
- SSSD should accept host entries from GPO's security filter (jsc#SLE-9298)
Список пакетов
SUSE Linux Enterprise Server 12 SP5
libipa_hbac0-1.16.1-7.61.1
libsss_certmap0-1.16.1-7.61.1
libsss_idmap0-1.16.1-7.61.1
libsss_nss_idmap-devel-1.16.1-7.61.1
libsss_nss_idmap0-1.16.1-7.61.1
libsss_simpleifp0-1.16.1-7.61.1
python-sssd-config-1.16.1-7.61.1
sssd-1.16.1-7.61.1
sssd-ad-1.16.1-7.61.1
sssd-common-1.16.1-7.61.1
sssd-common-32bit-1.16.1-7.61.1
sssd-dbus-1.16.1-7.61.1
sssd-ipa-1.16.1-7.61.1
sssd-krb5-1.16.1-7.61.1
sssd-krb5-common-1.16.1-7.61.1
sssd-ldap-1.16.1-7.61.1
sssd-proxy-1.16.1-7.61.1
sssd-tools-1.16.1-7.61.1
SUSE Linux Enterprise Server for SAP Applications 12 SP5
libipa_hbac0-1.16.1-7.61.1
libsss_certmap0-1.16.1-7.61.1
libsss_idmap0-1.16.1-7.61.1
libsss_nss_idmap-devel-1.16.1-7.61.1
libsss_nss_idmap0-1.16.1-7.61.1
libsss_simpleifp0-1.16.1-7.61.1
python-sssd-config-1.16.1-7.61.1
sssd-1.16.1-7.61.1
sssd-ad-1.16.1-7.61.1
sssd-common-1.16.1-7.61.1
sssd-common-32bit-1.16.1-7.61.1
sssd-dbus-1.16.1-7.61.1
sssd-ipa-1.16.1-7.61.1
sssd-krb5-1.16.1-7.61.1
sssd-krb5-common-1.16.1-7.61.1
sssd-ldap-1.16.1-7.61.1
sssd-proxy-1.16.1-7.61.1
sssd-tools-1.16.1-7.61.1
SUSE Linux Enterprise Software Development Kit 12 SP5
libipa_hbac-devel-1.16.1-7.61.1
libsss_idmap-devel-1.16.1-7.61.1
libsss_nss_idmap-devel-1.16.1-7.61.1
Ссылки
- Link for SUSE-SU-2024:1577-1
- E-Mail link for SUSE-SU-2024:1577-1
- SUSE Security Ratings
- SUSE Bug 1160688
- SUSE Bug 1223100
- SUSE CVE CVE-2023-3758 page
Описание
A race condition flaw was found in sssd where the GPO policy is not consistently applied for authenticated users. This may lead to improper authorization issues, granting or denying access to resources inappropriately.
Затронутые продукты
SUSE Linux Enterprise Server 12 SP5:libipa_hbac0-1.16.1-7.61.1
SUSE Linux Enterprise Server 12 SP5:libsss_certmap0-1.16.1-7.61.1
SUSE Linux Enterprise Server 12 SP5:libsss_idmap0-1.16.1-7.61.1
SUSE Linux Enterprise Server 12 SP5:libsss_nss_idmap-devel-1.16.1-7.61.1
Ссылки
- CVE-2023-3758
- SUSE Bug 1223100