SUSE-SU-2019:0081-1
Dashboard / Vulnerabilities / SUSE-SU-2019:0081-1
SUSE-SU-2019:0081-1
Summary: Security update for sssd
Details: This update for sssd provides the following fixes: This security issue was fixed: - CVE-2018-10852: Set stricter permissions on /var/lib/sss/pipes/sudo to prevent the disclosure of sudo rules for arbitrary users (bsc#1098377) These non-security issues were fixed: - Fix a segmentation fault in sss_cache command. (bsc#1072728) - Fix a failure in autofs initialisation sequence upon system boot. (bsc#1010700) - Fix race condition on boot between SSSD and autofs. (bsc#1010700) - Fix a bug where file descriptors were not closed (bsc#1080156) - Fix an issue where sssd logs were not rotated properly (bsc#1080156) - Remove whitespaces from netgroup entries (bsc#1087320) - Remove misleading log messages (bsc#1101877) - exit() the forked process if exec()-ing a child process fails (bsc#1110299) - Do not schedule the machine renewal task if adcli is not executable (bsc#1110299)
References: https://www.suse.com/support/update/announcement/2019/suse-su-20190081-1/, https://bugzilla.suse.com/1010700, https://bugzilla.suse.com/1072728, https://bugzilla.suse.com/1080156, https://bugzilla.suse.com/1087320, https://bugzilla.suse.com/1098377, https://bugzilla.suse.com/1101877, https://bugzilla.suse.com/1110299, https://www.suse.com/security/cve/CVE-2018-10852
Affected packages
Package
Name: sssd
Purl: pkg:rpm/suse/sssd&distro=SUSE%20OpenStack%20Cloud%207
Affected ranges
Type: ECOSYSTEM
Events:
