SUSE-SU-2022:2763-1
Dashboard / Vulnerabilities / SUSE-SU-2022:2763-1
SUSE-SU-2022:2763-1
Summary: Security update for sssd
Details: This update for sssd fixes the following issues: - CVE-2021-3621: Fixed shell command injection in sssctl via the logs-fetch and cache-expire subcommand (bsc#1189492). - Add 'ldap_ignore_unreadable_references' parameter to skip unreadable objects referenced by 'member' attributte (bsc#1190775) - Fix 32-bit libraries package. Libraries were moved from sssd to sssd-common but baselibs.conf was not updated accordingly (bsc#1182058, bsc#1196166) - Remove caches only when performing a package downgrade. The sssd daemon takes care of upgrading the database format when necessary (bsc#1195552)
References: https://www.suse.com/support/update/announcement/2022/suse-su-20222763-1/, https://bugzilla.suse.com/1182058, https://bugzilla.suse.com/1189492, https://bugzilla.suse.com/1190775, https://bugzilla.suse.com/1195552, https://bugzilla.suse.com/1196166, https://www.suse.com/security/cve/CVE-2021-3621
Affected packages
Package
Name: sssd
Purl: pkg:rpm/suse/sssd&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP4
Affected ranges
Type: ECOSYSTEM
Events:
