Executive Summary
Summary | |
---|---|
Title | sssd security and bug fix update |
Informations | |||
---|---|---|---|
Name | RHSA-2013:0663 | First vendor Publication | 2013-03-19 |
Vendor | RedHat | Last vendor Modification | 2013-03-19 |
Severity (Vendor) | Moderate | Revision | 01 |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:N/AC:M/Au:S/C:P/I:P/A:N) | |||
---|---|---|---|
Cvss Base Score | 4.9 | Attack Range | Network |
Cvss Impact Score | 4.9 | Attack Complexity | Medium |
Cvss Expoit Score | 6.8 | Authentication | Requires single instance |
Calculate full CVSS 2.0 Vectors scores |
Detail
Problem Description: Updated sssd packages that fix one security issue and two bugs are now available for Red Hat Enterprise Linux 6. The Red Hat Security Response Team has rated this update as having moderate security impact. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available from the CVE link in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux Desktop (v. 6) - i386, x86_64 Red Hat Enterprise Linux Desktop Optional (v. 6) - i386, x86_64 Red Hat Enterprise Linux HPC Node (v. 6) - x86_64 Red Hat Enterprise Linux HPC Node Optional (v. 6) - x86_64 Red Hat Enterprise Linux Server (v. 6) - i386, ppc64, s390x, x86_64 Red Hat Enterprise Linux Server Optional (v. 6) - i386, ppc64, s390x, x86_64 Red Hat Enterprise Linux Workstation (v. 6) - i386, x86_64 Red Hat Enterprise Linux Workstation Optional (v. 6) - i386, x86_64 3. Description: SSSD (System Security Services Daemon) provides a set of daemons to manage access to remote directories and authentication mechanisms. It provides NSS (Name Service Switch) and PAM (Pluggable Authentication Modules) interfaces toward the system and a pluggable back end system to connect to multiple different account sources. When SSSD was configured as a Microsoft Active Directory client by using the new Active Directory provider (introduced in RHSA-2013:0508), the Simple Access Provider ("access_provider = simple" in "/etc/sssd/sssd.conf") did not handle access control correctly. If any groups were specified with the "simple_deny_groups" option (in sssd.conf), all users were permitted access. (CVE-2013-0287) The CVE-2013-0287 issue was discovered by Kaushik Banerjee of Red Hat. This update also fixes the following bugs: * If a group contained a member whose Distinguished Name (DN) pointed out of any of the configured search bases, the search request that was processing this particular group never ran to completion. To the user, this bug manifested as a long timeout between requesting the group data and receiving the result. A patch has been provided to address this bug and SSSD now processes group search requests without delays. (BZ#907362) * The pwd_expiration_warning should have been set for seven days, but instead it was set to zero for Kerberos. This incorrect zero setting returned the "always display warning if the server sends one" error message and users experienced problems in environments like IPA or Active Directory. Currently, the value setting for Kerberos is modified and this issue no longer occurs. (BZ#914671) All users of sssd are advised to upgrade to these updated packages, which contain backported patches to correct these issues. 4. Solution: Before applying this update, make sure all previously-released errata relevant to your system have been applied. This update is available via the Red Hat Network. Details on how to use the Red Hat Network to apply this update are available at https://access.redhat.com/knowledge/articles/11258 5. Bugs fixed (http://bugzilla.redhat.com/): 910938 - CVE-2013-0287 sssd: simple access provider flaw prevents intended ACL use when client to an AD provider 914671 - pwd_expiration_warning has wrong default for Kerberos |
Original Source
Url : https://rhn.redhat.com/errata/RHSA-2013-0663.html |
CWE : Common Weakness Enumeration
% | Id | Name |
---|---|---|
100 % | CWE-264 | Permissions, Privileges, and Access Controls |
OVAL Definitions
Definition Id: oval:org.mitre.oval:def:20721 | |||
Oval ID: | oval:org.mitre.oval:def:20721 | ||
Title: | RHSA-2013:0663: sssd security and bug fix update (Moderate) | ||
Description: | The Simple Access Provider in System Security Services Daemon (SSSD) 1.9.0 through 1.9.4, when the Active Directory provider is used, does not properly enforce the simple_deny_groups option, which allows remote authenticated users to bypass intended access restrictions. | ||
Family: | unix | Class: | patch |
Reference(s): | RHSA-2013:0663-01 CESA-2013:0663 CVE-2013-0287 | Version: | 4 |
Platform(s): | Red Hat Enterprise Linux 6 CentOS Linux 6 | Product(s): | sssd |
Definition Synopsis: | |||
|
Definition Id: oval:org.mitre.oval:def:27145 | |||
Oval ID: | oval:org.mitre.oval:def:27145 | ||
Title: | DEPRECATED: ELSA-2013-0663 -- sssd security and bug fix update (moderate) | ||
Description: | [1.9.2-82.4] - Resolves: rhbz#911298 - sssd: simple access provider flaw prevents intended ACL use when client to an AD provider [1.9.2-82.3] - Fix pwd_expiration_warning=0 - Resolves: rhbz#914671 - pwd_expiration_warning has wrong default for Kerberos [1.9.2-82.2] - Resolves: rhbz#914671 - pwd_expiration_warning has wrong default for Kerberos - Fix the NVR [1.9.2-82.1] - Resolves: rhbz#907362 - Serious performance regression in sssd | ||
Family: | unix | Class: | patch |
Reference(s): | ELSA-2013-0663 CVE-2013-0287 | Version: | 4 |
Platform(s): | Oracle Linux 6 | Product(s): | sssd |
Definition Synopsis: | |||
|
CPE : Common Platform Enumeration
Type | Description | Count |
---|---|---|
Application | 5 |
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2014-06-13 | Name : The remote openSUSE host is missing a security update. File : openSUSE-2013-264.nasl - Type : ACT_GATHER_INFO |
2013-07-12 | Name : The remote Oracle Linux host is missing one or more security updates. File : oraclelinux_ELSA-2013-0663.nasl - Type : ACT_GATHER_INFO |
2013-04-01 | Name : The remote Fedora host is missing a security update. File : fedora_2013-4193.nasl - Type : ACT_GATHER_INFO |
2013-03-21 | Name : The remote CentOS host is missing one or more security updates. File : centos_RHSA-2013-0663.nasl - Type : ACT_GATHER_INFO |
2013-03-20 | Name : The remote Red Hat host is missing one or more security updates. File : redhat-RHSA-2013-0663.nasl - Type : ACT_GATHER_INFO |
2013-03-20 | Name : The remote Scientific Linux host is missing one or more security updates. File : sl_20130319_sssd_on_SL6_x.nasl - Type : ACT_GATHER_INFO |
Alert History
Date | Informations |
---|---|
2014-02-17 11:57:03 |
|
2013-03-22 21:19:36 |
|
2013-03-21 21:19:22 |
|
2013-03-19 21:17:31 |
|