Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

openSUSE-SU-2019:1589-1

Опубликовано: 19 июн. 2019
Источник: suse-cvrf

Описание

Security update for sssd

This update for sssd fixes the following issues:

Security issue fixed:

  • CVE-2018-16838: Fixed an authentication bypass related to the Group Policy Objects implementation (bsc#1124194).

Non-security issues fixed:

  • Allow defaults sudoRole without sudoUser attribute (bsc#1135247)
  • Missing GPOs directory could have led to login problems (bsc#1132879)
  • Fix a crash by adding a netgroup counter to struct nss_enum_index (bsc#1132657)

This update was imported from the SUSE:SLE-15:Update update project.

Список пакетов

openSUSE Leap 15.0
libipa_hbac-devel-1.16.1-lp151.7.3.1
libipa_hbac0-1.16.1-lp151.7.3.1
libnfsidmap-sss-1.16.1-lp151.7.3.1
libsss_certmap-devel-1.16.1-lp151.7.3.1
libsss_certmap0-1.16.1-lp151.7.3.1
libsss_idmap-devel-1.16.1-lp151.7.3.1
libsss_idmap0-1.16.1-lp151.7.3.1
libsss_nss_idmap-devel-1.16.1-lp151.7.3.1
libsss_nss_idmap0-1.16.1-lp151.7.3.1
libsss_simpleifp-devel-1.16.1-lp151.7.3.1
libsss_simpleifp0-1.16.1-lp151.7.3.1
python3-ipa_hbac-1.16.1-lp151.7.3.1
python3-sss-murmur-1.16.1-lp151.7.3.1
python3-sss_nss_idmap-1.16.1-lp151.7.3.1
python3-sssd-config-1.16.1-lp151.7.3.1
sssd-1.16.1-lp151.7.3.1
sssd-32bit-1.16.1-lp151.7.3.1
sssd-ad-1.16.1-lp151.7.3.1
sssd-dbus-1.16.1-lp151.7.3.1
sssd-ipa-1.16.1-lp151.7.3.1
sssd-krb5-1.16.1-lp151.7.3.1
sssd-krb5-common-1.16.1-lp151.7.3.1
sssd-ldap-1.16.1-lp151.7.3.1
sssd-proxy-1.16.1-lp151.7.3.1
sssd-tools-1.16.1-lp151.7.3.1
sssd-wbclient-1.16.1-lp151.7.3.1
sssd-wbclient-devel-1.16.1-lp151.7.3.1
sssd-winbind-idmap-1.16.1-lp151.7.3.1
openSUSE Leap 15.1
libipa_hbac-devel-1.16.1-lp151.7.3.1
libipa_hbac0-1.16.1-lp151.7.3.1
libnfsidmap-sss-1.16.1-lp151.7.3.1
libsss_certmap-devel-1.16.1-lp151.7.3.1
libsss_certmap0-1.16.1-lp151.7.3.1
libsss_idmap-devel-1.16.1-lp151.7.3.1
libsss_idmap0-1.16.1-lp151.7.3.1
libsss_nss_idmap-devel-1.16.1-lp151.7.3.1
libsss_nss_idmap0-1.16.1-lp151.7.3.1
libsss_simpleifp-devel-1.16.1-lp151.7.3.1
libsss_simpleifp0-1.16.1-lp151.7.3.1
python3-ipa_hbac-1.16.1-lp151.7.3.1
python3-sss-murmur-1.16.1-lp151.7.3.1
python3-sss_nss_idmap-1.16.1-lp151.7.3.1
python3-sssd-config-1.16.1-lp151.7.3.1
sssd-1.16.1-lp151.7.3.1
sssd-32bit-1.16.1-lp151.7.3.1
sssd-ad-1.16.1-lp151.7.3.1
sssd-dbus-1.16.1-lp151.7.3.1
sssd-ipa-1.16.1-lp151.7.3.1
sssd-krb5-1.16.1-lp151.7.3.1
sssd-krb5-common-1.16.1-lp151.7.3.1
sssd-ldap-1.16.1-lp151.7.3.1
sssd-proxy-1.16.1-lp151.7.3.1
sssd-tools-1.16.1-lp151.7.3.1
sssd-wbclient-1.16.1-lp151.7.3.1
sssd-wbclient-devel-1.16.1-lp151.7.3.1
sssd-winbind-idmap-1.16.1-lp151.7.3.1

Описание

A flaw was found in sssd Group Policy Objects implementation. When the GPO is not readable by SSSD due to a too strict permission settings on the server side, SSSD will allow all authenticated users to login instead of denying access.


Затронутые продукты
openSUSE Leap 15.0:libipa_hbac-devel-1.16.1-lp151.7.3.1
openSUSE Leap 15.0:libipa_hbac0-1.16.1-lp151.7.3.1
openSUSE Leap 15.0:libnfsidmap-sss-1.16.1-lp151.7.3.1
openSUSE Leap 15.0:libsss_certmap-devel-1.16.1-lp151.7.3.1

Ссылки