[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248678

 
 

909

 
 

195426

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

ALAS-2018-1127 --- sssd, python27, libsss_certmap, libsss_autofs, libsss_nss_idmap, libsss_sudo, libsss_idmap, libipa_hbac

ID: oval:org.secpod.oval:def:1601372Date: (C)2020-11-27   (M)2022-10-27
Class: PATCHFamily: unix




The UNIX pipe which sudo uses to contact SSSD and read the available sudo rules from SSSD utilizes too broad of a set of permissions. Any user who can send a message using the same raw protocol that sudo and SSSD use can read the sudo rules available for any user

Platform:
Amazon Linux AMI
Product:
sssd
python27
libsss_certmap
libsss_autofs
libsss_nss_idmap
libsss_sudo
libsss_idmap
libipa_hbac
Reference:
ALAS-2018-1127
CVE-2018-10852
CVE    1
CVE-2018-10852
CPE    4
cpe:/o:amazon:linux
cpe:/a:sssd:libsss_certmap
cpe:/a:sssd:sssd
cpe:/a:python:python27
...

© SecPod Technologies