Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2024:1577-1

Опубликовано: 09 мая 2024
Источник: suse-cvrf

Описание

Security update for sssd

This update for sssd fixes the following issues:

Security fixes:

  • CVE-2023-3758: Fixed race condition during authorization that lead to GPO policies functioning inconsistently (bsc#1223100)

Other fixes:

  • Extend sssctl command line tool to manage the cached GPOs (jsc#PED-7677)
  • SSSD GPO host entries are ignored if computer cn does not match it's samaccountname (jsc#SLE-9298) (bsc#1160688)
  • SSSD should accept host entries from GPO's security filter (jsc#SLE-9298)

Список пакетов

SUSE Linux Enterprise Server 12 SP5
libipa_hbac0-1.16.1-7.61.1
libsss_certmap0-1.16.1-7.61.1
libsss_idmap0-1.16.1-7.61.1
libsss_nss_idmap-devel-1.16.1-7.61.1
libsss_nss_idmap0-1.16.1-7.61.1
libsss_simpleifp0-1.16.1-7.61.1
python-sssd-config-1.16.1-7.61.1
sssd-1.16.1-7.61.1
sssd-ad-1.16.1-7.61.1
sssd-common-1.16.1-7.61.1
sssd-common-32bit-1.16.1-7.61.1
sssd-dbus-1.16.1-7.61.1
sssd-ipa-1.16.1-7.61.1
sssd-krb5-1.16.1-7.61.1
sssd-krb5-common-1.16.1-7.61.1
sssd-ldap-1.16.1-7.61.1
sssd-proxy-1.16.1-7.61.1
sssd-tools-1.16.1-7.61.1
SUSE Linux Enterprise Server for SAP Applications 12 SP5
libipa_hbac0-1.16.1-7.61.1
libsss_certmap0-1.16.1-7.61.1
libsss_idmap0-1.16.1-7.61.1
libsss_nss_idmap-devel-1.16.1-7.61.1
libsss_nss_idmap0-1.16.1-7.61.1
libsss_simpleifp0-1.16.1-7.61.1
python-sssd-config-1.16.1-7.61.1
sssd-1.16.1-7.61.1
sssd-ad-1.16.1-7.61.1
sssd-common-1.16.1-7.61.1
sssd-common-32bit-1.16.1-7.61.1
sssd-dbus-1.16.1-7.61.1
sssd-ipa-1.16.1-7.61.1
sssd-krb5-1.16.1-7.61.1
sssd-krb5-common-1.16.1-7.61.1
sssd-ldap-1.16.1-7.61.1
sssd-proxy-1.16.1-7.61.1
sssd-tools-1.16.1-7.61.1
SUSE Linux Enterprise Software Development Kit 12 SP5
libipa_hbac-devel-1.16.1-7.61.1
libsss_idmap-devel-1.16.1-7.61.1
libsss_nss_idmap-devel-1.16.1-7.61.1

Описание

A race condition flaw was found in sssd where the GPO policy is not consistently applied for authenticated users. This may lead to improper authorization issues, granting or denying access to resources inappropriately.


Затронутые продукты
SUSE Linux Enterprise Server 12 SP5:libipa_hbac0-1.16.1-7.61.1
SUSE Linux Enterprise Server 12 SP5:libsss_certmap0-1.16.1-7.61.1
SUSE Linux Enterprise Server 12 SP5:libsss_idmap0-1.16.1-7.61.1
SUSE Linux Enterprise Server 12 SP5:libsss_nss_idmap-devel-1.16.1-7.61.1

Ссылки