LWN.net Logo

sssd: file modification and denial of service

Package(s):sssd CVE #(s):CVE-2013-0220 CVE-2013-0219
Created:February 10, 2013 Updated:March 11, 2013
Description: The system security services daemon suffers from two vulnerabilities:

  • A race condition in the copying and removal of user directory trees could enable symbolic link attacks by a local attacker, possibly leading to the removal or modification of arbitrary directory trees.

  • Various out-of-bound read flaws could be exploited via a hostile packet to crash the sssd server.
Alerts:
Fedora FEDORA-2013-1795 2013-02-09
Fedora FEDORA-2013-1826 2013-02-12
Red Hat RHSA-2013:0508-02 2013-02-21
Oracle ELSA-2013-0508 2013-02-28
Scientific Linux SL-sssd-20130304 2013-03-04
CentOS CESA-2013:0508 2013-03-09

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds