Alerts This Week
Warning Icon 1 677
Alerts This Week
Warning Icon 1 677

SUSE Linux Enterprise Server 12: SUSE-SU-2019:0552-1 Moderate: SSSD Threat

suse
Calendar Grey March 6, 2019
Dist Suse Esm H88
SUSE Security Update: Security update for sssd _____________________________________________________
An update that solves one vulnerability and has four fixes is now available

Summary

This update for sssd fixes the following issues: Security vulnerability fixed: - CVE-2019-3811: Fix fallback_homedir returning '/' for empty home directories (bsc#1121759) Other bug fixes and changes: - Skip sdap_save_grpmem() if ignore_group_members is set. (bsc#1082568) - Only search for primary group if it is not already cached (bsc#1082568) - Install /var/lib/sss/mc directory to correct sssd cache invalidation behaviour. Spec patch authored by Josef Cejka. (bsc#1039567) to fix a segfault in sudo provider (bsc#977224). - Fix a segfault in sss_cache (bsc#976038). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product:

References

#1039567 #1082568 #1121759 #976038 #977224

Cross- CVE-2019-3811

Affected Products:

SUSE Linux Enterprise Server 12-LTSS

https://www.suse.com/security/cve/CVE-2019-3811.html

https://bugzilla.suse.com/1039567

https://bugzilla.suse.com/1082568

https://bugzilla.suse.com/1121759

https://bugzilla.suse.com/976038

https://bugzilla.suse.com/977224

Announcement ID: SUSE-SU-2019:0552-1
Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here