Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

Debian 10: DLA-3436-1 Moderate: SSSD Privilege Escalation Threats

debian lts
Calendar Grey May 29, 2023
Dist Debian Esm H88
Debian LTS Advisory DLA-3437-1 highlights several vulnerabilities in sssd that could allow for unauthorized privilege escalation, necessitating an immediate update.
Multiple vulnerabilities were found in sssd, a set of daemons to manage access to remote directories and authentication mechanisms, which could lead to privilege escalation

Summary

It was discovered that when the Group Policy Objects (GPO) are not
readable by SSSD due to a too strict permission settings on the
server side, SSSD allows all authenticated users to login instead of
denying access.

A new boolean setting ‘ad_gpo_ignore_unreadable’ (defaulting to
False) is introduced for environments where attributes in the
groupPolicyContainer are not readable and changing the permissions
on the GPO objects is not possible or desirable. See sssd-ad(5).

CVE-2019-3811

It was discovered that if a user was configured with no home
directory set, then sssd(8) returns ‘/’ (i.e., the root directory)
instead of the empty string (meaning no home directory). This could
impact services that restrict the user's filesystem access to within
their home directory through chroot() or similar.

CVE-2021-3621

It was discovered that the sssctl(8) command was vulnerable to shell

Read the Full Advisory


Severity
medium
Lowest
Low
Medium
High
Critical

-------------------------------------------------------------------------Package: sssd
Version: 1.16.3-3.2+deb10u1
CVE ID: CVE-2018-16838 CVE-2019-3811 CVE-2021-3621 CVE-2022-4254
Debian Bug: 919051 931432 992710

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here