The Debian courier-authlib package before 0.71.1-2 for Courier Authentication Library creates a /run/courier/authdaemon directory with weak permissions, allowing an attacker to read user information. This may include a cleartext password in some . - ----------------------------------------------------------------------- Debian LTS Advisory DLA-2625-1
It was discovered that zstd, a compression utility, temporarily exposed a world-readable version of its input even if the original file had restrictive permissions. . - ------------------------------------------------------------------------- Debian Security Advisory DSA-4850-1
The UNIX pipe which sudo uses to contact SSSD and read the available sudo rules from SSSD has too wide permissions, which means that anyone who can send a message using the same raw protocol that sudo and SSSD use can read the sudo . Package : sssd Version : 1.11.7-3+deb8u1 CVE ID : CVE-2018-10852 Debian Bug : 902860 The UNIX pipe which sudo uses to contact SSSD and read the available sudo rules from SSSD has too wide permissions, which means that anyone who can send a message using the same raw protocol that sudo and SSSD use can read the sudo rules available for any user. For Debian 8 "Jessie", these problems have been fixed in version 1.11.7-3+deb8u1. We recommend that you upgrade your sssd packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Enhance SSSD performance on Debian 8 to resolve sudo rule visibility issues by backing up first, updating via package manager, tweaking configs, and restarting the service for best results. Sssd Security Update, Debian 8 Update, Permissions Exposure, Security Advisory. . Severity: Low. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.