PT-2013-1179 · Red Hat+1 · Red Hat+2

Florian Weimer

·

Published

2013-02-20

·

Updated

2024-06-15

·

CVE-2013-0219

CVSS v2.0

3.7

Low

VectorAV:L/AC:H/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions SSSD versions prior to 1.9.4 Red Hat Enterprise Linux (affected versions not specified)
Description The issue allows local users to create, modify, or delete arbitrary files via a symlink attack on another user's files, potentially leading to disruption of confidentiality, integrity, and availability of protected information. This can be exploited locally.
Recommendations For versions prior to 1.9.4, update to version 1.9.4 or later to resolve the issue. As a temporary workaround, consider restricting access to sensitive files and directories to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-06800
BDU:2015-06801
BDU:2015-06802
BDU:2015-06929
BDU:2015-06930
BDU:2015-06931
BDU:2015-06932
CESA-2013_0508
CVE-2013-0219
MGASA-2013-0158
OPENSUSE-SU-2024:10427-1
RHSA-2013:0508
RHSA-2013:1319
RHSA-2013_0508
RHSA-2013_1319

Affected Products

Centos
Red Hat
Sssd