PT-2018-3920 · Red Hat+5 · Sssd+6

Laura Pardo

·

Publicado

2018-06-26

·

Atualizado

2024-06-15

·

CVE-2018-10852

CVSS v2.0

7.8

Alta

VetorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions SSSD versions prior to 1.16.3
Description The issue is related to the UNIX pipe used by sudo to contact SSSD, which has overly permissive permissions. This allows anyone who can send messages using the same raw protocol as sudo and SSSD to read the available sudo rules for any user. The vulnerability can be exploited remotely, potentially allowing an attacker to access confidential data by sending specially crafted requests.
Recommendations For versions prior to 1.16.3, update to version 1.16.3 or later to resolve the issue. As a temporary workaround, consider restricting access to the SSSD service to minimize the risk of exploitation.

Correção

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2018-2235
BDU:2023-03473
CESA-2018_3158
CVE-2018-10852
DLA-1429-1
MGASA-2018-0350
OPENSUSE-SU-2018_2289-1
OPENSUSE-SU-2019_0051-1
OPENSUSE-SU-2024:11408-1
RHSA-2018:3158
RHSA-2018_3158
SUSE-SU-2018:2144-1
SUSE-SU-2018_2144-1
SUSE-SU-2019:0081-1
SUSE-SU-2019:0556-1
SUSE-SU-2019_0081-1
SUSE-SU-2019_0556-1
USN-5067-1

Produtos afetados

Alt Linux
Centos
Linuxmint
Red Hat
Sssd
Suse
Ubuntu