PT-2013-1187 · Red Hat+1 · Sssd+2

Kaushik Banerjee

·

Published

2013-03-19

·

Updated

2024-06-15

·

CVE-2013-0287

CVSS v2.0

4.9

Medium

VectorAV:N/AC:M/Au:S/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions SSSD versions 1.9.0 through 1.9.4 sssd version 1.9.2 sssd-client version 1.9.2 sssd-tools version 1.9.2 libipa hbac version 1.9.2 libipa hbac-devel version 1.9.2 libsss sudo version 1.9.2 libsss sudo-devel version 1.9.2 libipa hbac-python version 1.9.2 libsss idmap version 1.9.2 libsss idmap-devel version 1.9.2 libsss autofs version 1.9.2 sssd-debuginfo version 1.9.2
Description The vulnerability may lead to a breach of confidentiality and integrity of protected information. It can be exploited remotely by an attacker who has passed the authentication procedure. The Simple Access Provider in System Security Services Daemon (SSSD) does not properly enforce the simple deny groups option when the Active Directory provider is used, allowing remote authenticated users to bypass intended access restrictions.
Recommendations For SSSD versions 1.9.0 through 1.9.4, update to a version that properly enforces the simple deny groups option. For sssd version 1.9.2, consider disabling the vulnerable component until a patch is available. For sssd-client version 1.9.2, restrict access to the vulnerable module to minimize the risk of exploitation. For sssd-tools version 1.9.2, avoid using the vulnerable tool until the issue is resolved. For libipa hbac version 1.9.2, libipa hbac-devel version 1.9.2, libsss sudo version 1.9.2, libsss sudo-devel version 1.9.2, libipa hbac-python version 1.9.2, libsss idmap version 1.9.2, libsss idmap-devel version 1.9.2, libsss autofs version 1.9.2, and sssd-debuginfo version 1.9.2, update to a version that contains a fix for this vulnerability. At the moment, there is no information about a newer version that contains a fix for this vulnerability for some of the affected packages.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-07147
BDU:2015-07148
BDU:2015-07149
BDU:2015-07150
BDU:2015-07151
BDU:2015-07152
BDU:2015-07153
BDU:2015-07154
BDU:2015-07160
BDU:2015-07161
BDU:2015-07162
BDU:2015-07163
BDU:2015-08958
BDU:2015-08959
BDU:2015-08960
BDU:2015-08961
CESA-2013_0663
CVE-2013-0287
OPENSUSE-SU-2024:10427-1
RHSA-2013:0663
RHSA-2013_0663

Affected Products

Centos
Red Hat
Sssd