SUSE-SU-2016:2579-1

    Dashboard / Vulnerabilities / SUSE-SU-2016:2579-1

    SUSE-SU-2016:2579-1

    Published: 20 Oct 2016Last Modified: 4 Feb 2026
    Upstream:
    Aliases:

    Summary: Security update for sssd

    Details: This update for sssd fixes one security issue and three bugs. The following vulnerability was fixed: - CVE-2014-0249: Incorrect expansion of group membership when encountering a non-POSIX group. (bsc#880245) The following non-security fixes were also included: - Prevent crashes of statically linked binaries using getpwuid when sssd is used and nscd is turned off or has caching disabled. (bsc#993582) - Add logrotate configuration to prevent log files from growing too large when running with debug mode enabled. (bsc#1004220) - Order sudo rules by the same logic used by the native LDAP support from sudo. (bsc#1002973)

    Affected packages

    Package

    Name: sssd

    Purl: pkg:rpm/suse/sssd&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP1

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -1.11.5.1-28.1

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High