SUSE-SU-2016:2579-1
Dashboard / Vulnerabilities / SUSE-SU-2016:2579-1
SUSE-SU-2016:2579-1
Summary: Security update for sssd
Details: This update for sssd fixes one security issue and three bugs. The following vulnerability was fixed: - CVE-2014-0249: Incorrect expansion of group membership when encountering a non-POSIX group. (bsc#880245) The following non-security fixes were also included: - Prevent crashes of statically linked binaries using getpwuid when sssd is used and nscd is turned off or has caching disabled. (bsc#993582) - Add logrotate configuration to prevent log files from growing too large when running with debug mode enabled. (bsc#1004220) - Order sudo rules by the same logic used by the native LDAP support from sudo. (bsc#1002973)
References: https://www.suse.com/support/update/announcement/2016/suse-su-20162579-1/, https://bugzilla.suse.com/1002973, https://bugzilla.suse.com/1004220, https://bugzilla.suse.com/880245, https://bugzilla.suse.com/993582, https://www.suse.com/security/cve/CVE-2014-0249
Affected packages
Package
Name: sssd
Purl: pkg:rpm/suse/sssd&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP1
Affected ranges
Type: ECOSYSTEM
Events:
