MGASA-2017-0421
Dashboard / Vulnerabilities / MGASA-2017-0421
Summary: Updated sssd packages fix security vulnerability
Details: SSSD stores its cached data in an LDAP like local database file using libldb. To lookup cached data LDAP search filters like '(objectClass=user) (name=user_name)' are used. However, in sysdb_search_user_by_upn_res(), the input is not sanitized and allows to manipulate the search filter for cache lookups. This would allow a logged in user to discover the password hash of a different user (CVE-2017-12173).
References: https://advisories.mageia.org/MGASA-2017-0421.html, https://bugs.mageia.org/show_bug.cgi?id=21917, https://lists.opensuse.org/opensuse-updates/2017-11/msg00016.html
Affected packages
Package
Name: sssd
Purl: pkg:rpm/mageia/sssd?arch=source&distro=mageia-6
Affected ranges
Type: ECOSYSTEM
Events:
