Alerts This Week
Warning Icon 1 659
Alerts This Week
Warning Icon 1 659

SUSE: 2018:2144-1 Moderate: Fix for sssd Sudo Rules Disclosure

suse
Calendar Grey July 31, 2018
Dist Suse Esm H88
The SUSE team has issued a critical patch for sssd concerning CVE-2018-10852, rated with moderate severity. Ensure updates are applied without delay.
An update that solves one vulnerability and has one errata is now available

Summary

This update for sssd fixes the following security issue: - CVE-2018-10852: Set stricter permissions on /var/lib/sss/pipes/sudo to prevent the disclosure of sudo rules for arbitrary users (bsc#1098377). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Module for Basesystem 15: zypper in -t patch SUSE-SLE-Module-Basesystem-15-2018-1456=1 Package List: - SUSE Linux Enterprise Module for Basesystem 15 (aarch64 ppc64le s390x x86_64): libipa_hbac-devel-1.16.1-3.3.1 libipa_hbac0-1.16.1-3.3.1 libipa_hbac0-debuginfo-1.16.1-3.3.1 libsss_certmap-devel-1.16.1-3.3.1 libsss_certmap0-1.16.1-3.3.1

References

#1098163 #1098377

Cross- CVE-2018-10852

Affected Products:

SUSE Linux Enterprise Module for Basesystem 15

https://www.suse.com/security/cve/CVE-2018-10852.html

https://bugzilla.suse.com/1098163

https://bugzilla.suse.com/1098377

Announcement ID: SUSE-SU-2018:2144-1
Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here