Before applying this update, make sure all previously-released errata
relevant to your system have been applied.
This update is available via the Red Hat Network. Details on how to
use the Red Hat Network to apply this update are available at
https://access.redhat.com/knowledge/articles/11258
The System Security Services Daemon (SSSD) provides a set of daemons to
manage access to remote directories and authentication mechanisms. It
provides an NSS and PAM interface toward the system and a pluggable
back-end system to connect to multiple different account sources. It is
also the basis to provide client auditing and policy services for projects
such as FreeIPA.
A race condition was found in the way SSSD copied and removed user home
directories. A local attacker who is able to write into the home directory
of a different user who is being removed could use this flaw to perform
symbolic link attacks, possibly allowing them to modify and delete
arbitrary files with the privileges of the root user. (CVE-2013-0219)
Multiple out-of-bounds memory read flaws were found in the way the autofs
and SSH service responders parsed certain SSSD packets. An attacker could
spend a specially-crafted packet that, when processed by the autofs or SSH
service responders, would cause SSSD to crash. This issue only caused a
temporary denial of service, as SSSD was automatically restarted by the
monitor process after the crash. (CVE-2013-0220)
The CVE-2013-0219 and CVE-2013-0220 issues were discovered by Florian
Weimer of the Red Hat Product Security Team.
These updated sssd packages also include numerous bug fixes and
enhancements. Space precludes documenting all of these changes in this
advisory. Users are directed to the Red Hat Enterprise Linux 6.4 Technical
Notes, linked to in the References, for information on the most significant
of these changes.
All SSSD users are advised to upgrade to these updated packages, which
upgrade SSSD to upstream version 1.9 to correct these issues, fix these
bugs and add these enhancements.
https://access.redhat.com/security/cve/CVE-2013-0219 https://access.redhat.com/security/cve/CVE-2013-0220 https://access.redhat.com/security/updates/classification/#low
Red Hat Enterprise Linux Desktop (v. 6):
Source:
i386:
libipa_hbac-1.9.2-82.el6.i686.rpm
libipa_hbac-python-1.9.2-82.el6.i686.rpm
libsss_autofs-1.9.2-82.el6.i686.rpm
libsss_idmap-1.9.2-82.el6.i686.rpm
libsss_sudo-1.9.2-82.el6.i686.rpm
sssd-1.9.2-82.el6.i686.rpm
sssd-client-1.9.2-82.el6.i686.rpm
sssd-debuginfo-1.9.2-82.el6.i686.rpm
x86_64:
libipa_hbac-1.9.2-82.el6.i686.rpm
libipa_hbac-1.9.2-82.el6.x86_64.rpm
libipa_hbac-python-1.9.2-82.el6.x86_64.rpm
libsss_autofs-1.9.2-82.el6.x86_64.rpm
libsss_idmap-1.9.2-82.el6.x86_64.rpm
libsss_sudo-1.9.2-82.el6.x86_64.rpm
sssd-1.9.2-82.el6.x86_64.rpm
sssd-client-1.9.2-82.el6.i686.rpm
sssd-client-1.9.2-82.el6.x86_64.rpm
sssd-debuginfo-1.9.2-82.el6.i686.rpm
sssd-debuginfo-1.9.2-82.el6.x86_64.rpm
Red Hat Enterprise Linux Desktop Optional (v. 6):
Source:
i386:
libipa_hbac-devel-1.9.2-82.el6.i686.rpm
libsss_idmap-devel-1.9.2-82.el6.i686.rpm
libsss_sudo-devel-1.9.2-82.el6.i686.rpm
sssd-debuginfo-1.9.2-82.el6.i686.rpm
sssd-tools-1.9.2-82.el6.i686.rpm
x86_64:
libipa_hbac-devel-1.9.2-82.el6.i686.rpm
libipa_hbac-devel-1.9.2-82.el6.x86_64.rpm
libsss_idmap-1.9.2-82.el6.i686.rpm
libsss_idmap-devel-1.9.2-82.el6.i686.rpm
libsss_idmap-devel-1.9.2-82.el6.x86_64.rpm
libsss_sudo-devel-1.9.2-82.el6.i686.rpm
libsss_sudo-devel-1.9.2-82.el6.x86_64.rpm
Read the Full Advisory
Updated sssd packages that fix two security issues, multiple bugs, and addvarious enhancements are now available for Red Hat Enterprise Linux 6.The Red Hat Security Response Team has rated this update as having lowsecurity impact. Common Vulnerability Scoring System (CVSS) base scores,which give detailed severity ratings, are available for each vulnerabilityfrom the CVE links in the References section.
Red Hat Enterprise Linux Desktop (v. 6) - i386, x86_64
Red Hat Enterprise Linux Desktop Optional (v. 6) - i386, x86_64
Red Hat Enterprise Linux HPC Node (v. 6) - x86_64
Red Hat Enterprise Linux HPC Node Optional (v. 6) - x86_64
Red Hat Enterprise Linux Server (v. 6) - i386, ppc64, s390x, x86_64
Red Hat Enterprise Linux Server Optional (v. 6) - i386, ppc64, s390x, x86_64
Red Hat Enterprise Linux Workstation (v. 6) - i386, x86_64
Red Hat Enterprise Linux Workstation Optional (v. 6) - i386, x86_64
743505 - [RFE] Implement "AD friendly" schema mapping
761573 - [RFE] Integrate with SUDO utility
766000 - [RFE]Add support for central management of the SELinux user mappings
768165 - [RFE] Support range retrievals
768168 - [RFE] Allow Constructing uid from Active Directory objectSid
789470 - [RFE] Introduce the concept of a Primary Server in SSSD
789507 - [RFE] SSSD should provide fast in memory cache to provide similar functionality as NSCD currently provides
790105 - Filter out inappropriate IP addresses from IPA dynamic DNS update
790107 - Document sss_tools better
799009 - Warn to syslog when dereference requests fail
799928 - [RFE] Hash the hostname/port information in the known_hosts file.
801431 - [RFE] sudo: send username and uid while requesting default options
801719 - "Error looking up public keys" while ssh to replica using IP address.
802718 - Unable to lookup user aliases with proxy provider.
805920 - [RFE] Introduce concept of Ghost User instead of using Fake User
805921 - Document the expectations about ghost users showing in the lookups
808307 - No info in sssd manpages for "ldap_sasl_minssf"
811987 - autofs: maximum key name must be PATH_MAX
813327 - [RFE] support looking up autofs maps via SSSD
814249 - [RFE] for faster SSSD startup
822404 - sssd does not provide maps for automounter when custom schema is being used
824244 - sssd does not warn into sssd.log for broken configurations
Get the latest Linux and open source security news straight to your inbox.