LWN.net Logo

sssd: privilege violation

Package(s):sssd CVE #(s):CVE-2013-0287
Created:March 20, 2013 Updated:April 1, 2013
Description: From the Red Hat advisory:

When SSSD was configured as a Microsoft Active Directory client by using the new Active Directory provider (introduced in RHSA-2013:0508), the Simple Access Provider ("access_provider = simple" in "/etc/sssd/sssd.conf") did not handle access control correctly. If any groups were specified with the "simple_deny_groups" option (in sssd.conf), all users were permitted access.

Alerts:
Red Hat RHSA-2013:0663-01 2013-03-19
CentOS CESA-2013:0663 2013-03-19
Oracle ELSA-2013-0663 2013-03-19
Scientific Linux SL-sssd-20130319 2013-03-19
openSUSE openSUSE-SU-2013:0559-1 2013-03-28
Fedora FEDORA-2013-4193 2013-03-30

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds