PT-2015-6836 · Red Hat+2 · Sssd+3
Martin Prpič
·
Published
2014-04-28
·
Updated
2023-02-13
·
CVE-2015-5292
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:L/Au:S/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
System Security Services Daemon (SSSD) versions 1.10 through 1.13.0
Description
The issue is related to a memory leak in the Privilege Attribute Certificate (PAC) responder plugin, which can be triggered by remote authenticated users through a large number of logins during Kerberos authentication, leading to a denial of service due to memory consumption.
Recommendations
For versions 1.10 through 1.13.0, update to version 1.13.1 or later to resolve the issue.
Fix
DoS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Centos
Red Hat
Sssd