Alerts This Week
Warning Icon 1 692
Alerts This Week
Warning Icon 1 692

Debian 9: DLA-2758-1 Critical: SSSD Shell Command Injection Threat

debian lts
Calendar Grey September 15, 2021
Dist Debian Esm H88
Ubuntu Security Notice USN-5294-1 addresses a critical vulnerability in the apparmor package, exposing systems to unauthorized access risks.
One security issue has been discovered in sssd

Summary

The sssctl command was vulnerable to shell command injection via the logs-fetch
and cache-expire subcommands. This flaw allows an attacker to trick the root
user into running a specially crafted sssctl command, such as via sudo, to gain
root access. The highest threat from this vulnerability is to confidentiality,
integrity, as well as system availability.

For Debian 9 stretch, this problem has been fixed in version
1.15.0-3+deb9u2.

We recommend that you upgrade your sssd packages.

For the detailed security status of sssd please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/source-package/sssd

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS


Severity
critical
Lowest
Low
Medium
High
Critical

Package: sssd
Version: 1.15.0-3+deb9u2
CVE ID: CVE-2021-3621

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here