PT-2018-3920 · Red Hat+5 · Sssd+6
Laura Pardo
·
Publicado
2018-06-26
·
Atualizado
2024-06-15
·
CVE-2018-10852
CVSS v2.0
7.8
Alta
| Vetor | AV:N/AC:L/Au:N/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
SSSD versions prior to 1.16.3
Description
The issue is related to the UNIX pipe used by sudo to contact SSSD, which has overly permissive permissions. This allows anyone who can send messages using the same raw protocol as sudo and SSSD to read the available sudo rules for any user. The vulnerability can be exploited remotely, potentially allowing an attacker to access confidential data by sending specially crafted requests.
Recommendations
For versions prior to 1.16.3, update to version 1.16.3 or later to resolve the issue. As a temporary workaround, consider restricting access to the SSSD service to minimize the risk of exploitation.
Correção
Information Disclosure
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Alt Linux
Centos
Linuxmint
Red Hat
Sssd
Suse
Ubuntu