|
|
| |
|
| |
sssd: file modification and denial of service
| Package(s): | sssd |
CVE #(s): | CVE-2013-0220
CVE-2013-0219
|
| Created: | February 10, 2013 |
Updated: | March 11, 2013 |
| Description: |
The system security services daemon suffers from two vulnerabilities:
- A race condition in the copying and removal of user directory trees could enable symbolic link attacks by a local attacker, possibly leading to the removal or modification of arbitrary directory trees.
- Various out-of-bound read flaws could be exploited via a hostile packet to crash the sssd server.
|
| Alerts: |
|
( Log in to post comments)
|
|
|