Download
| Alert*
ALAS-2017-875 ---- authconfig
Information leak when SSSD is used for authentication against remote server:A flaw was found where authconfig could configure sssd in a way that treats existing and non-existing logins differently, leaking information on existence of a user. An attacker with physical or network access to the machine could enumerate users via a timing attack.
|