vulnerability

CentOS Linux: CVE-2019-3811: Moderate: sssd security, bug fix, and enhancement update (CESA-2019:2177)

Severity
3
CVSS
(AV:A/AC:L/Au:S/C:N/I:N/A:P)
Published
Jan 15, 2019
Added
Aug 28, 2019
Modified
May 25, 2023

Description

A vulnerability was found in sssd. If a user was configured with no home directory set, sssd would return '/' (the root directory) instead of '' (the empty string / no home directory). This could impact services that restrict the user's filesystem access to within their home directory through chroot() etc. All versions before 2.1 are vulnerable.

Solution(s)

centos-upgrade-libipa_hbaccentos-upgrade-libipa_hbac-develcentos-upgrade-libsss_autofscentos-upgrade-libsss_certmapcentos-upgrade-libsss_certmap-develcentos-upgrade-libsss_idmapcentos-upgrade-libsss_idmap-develcentos-upgrade-libsss_nss_idmapcentos-upgrade-libsss_nss_idmap-develcentos-upgrade-libsss_simpleifpcentos-upgrade-libsss_simpleifp-develcentos-upgrade-libsss_sudocentos-upgrade-python-libipa_hbaccentos-upgrade-python-libsss_nss_idmapcentos-upgrade-python-ssscentos-upgrade-python-sss-murmurcentos-upgrade-python-sssdconfigcentos-upgrade-sssdcentos-upgrade-sssd-adcentos-upgrade-sssd-clientcentos-upgrade-sssd-commoncentos-upgrade-sssd-common-paccentos-upgrade-sssd-dbuscentos-upgrade-sssd-debuginfocentos-upgrade-sssd-ipacentos-upgrade-sssd-kcmcentos-upgrade-sssd-krb5centos-upgrade-sssd-krb5-commoncentos-upgrade-sssd-ldapcentos-upgrade-sssd-libwbclientcentos-upgrade-sssd-libwbclient-develcentos-upgrade-sssd-polkit-rulescentos-upgrade-sssd-proxycentos-upgrade-sssd-toolscentos-upgrade-sssd-winbind-idmap
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.