Executive Summary

Summary
Title sssd security and bug fix update
Informations
Name RHSA-2013:0663 First vendor Publication 2013-03-19
Vendor RedHat Last vendor Modification 2013-03-19
Severity (Vendor) Moderate Revision 01

Security-Database Scoring CVSS v3

Cvss vector : N/A
Overall CVSS Score NA
Base Score NA Environmental Score NA
impact SubScore NA Temporal Score NA
Exploitabality Sub Score NA
 
Calculate full CVSS 3.0 Vectors scores

Security-Database Scoring CVSS v2

Cvss vector : (AV:N/AC:M/Au:S/C:P/I:P/A:N)
Cvss Base Score 4.9 Attack Range Network
Cvss Impact Score 4.9 Attack Complexity Medium
Cvss Expoit Score 6.8 Authentication Requires single instance
Calculate full CVSS 2.0 Vectors scores

Detail

Problem Description:

Updated sssd packages that fix one security issue and two bugs are now available for Red Hat Enterprise Linux 6.

The Red Hat Security Response Team has rated this update as having moderate security impact. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available from the CVE link in the References section.

2. Relevant releases/architectures:

Red Hat Enterprise Linux Desktop (v. 6) - i386, x86_64 Red Hat Enterprise Linux Desktop Optional (v. 6) - i386, x86_64 Red Hat Enterprise Linux HPC Node (v. 6) - x86_64 Red Hat Enterprise Linux HPC Node Optional (v. 6) - x86_64 Red Hat Enterprise Linux Server (v. 6) - i386, ppc64, s390x, x86_64 Red Hat Enterprise Linux Server Optional (v. 6) - i386, ppc64, s390x, x86_64 Red Hat Enterprise Linux Workstation (v. 6) - i386, x86_64 Red Hat Enterprise Linux Workstation Optional (v. 6) - i386, x86_64

3. Description:

SSSD (System Security Services Daemon) provides a set of daemons to manage access to remote directories and authentication mechanisms. It provides NSS (Name Service Switch) and PAM (Pluggable Authentication Modules) interfaces toward the system and a pluggable back end system to connect to multiple different account sources.

When SSSD was configured as a Microsoft Active Directory client by using the new Active Directory provider (introduced in RHSA-2013:0508), the Simple Access Provider ("access_provider = simple" in "/etc/sssd/sssd.conf") did not handle access control correctly. If any groups were specified with the "simple_deny_groups" option (in sssd.conf), all users were permitted access. (CVE-2013-0287)

The CVE-2013-0287 issue was discovered by Kaushik Banerjee of Red Hat.

This update also fixes the following bugs:

* If a group contained a member whose Distinguished Name (DN) pointed out of any of the configured search bases, the search request that was processing this particular group never ran to completion. To the user, this bug manifested as a long timeout between requesting the group data and receiving the result. A patch has been provided to address this bug and SSSD now processes group search requests without delays. (BZ#907362)

* The pwd_expiration_warning should have been set for seven days, but instead it was set to zero for Kerberos. This incorrect zero setting returned the "always display warning if the server sends one" error message and users experienced problems in environments like IPA or Active Directory. Currently, the value setting for Kerberos is modified and this issue no longer occurs. (BZ#914671)

All users of sssd are advised to upgrade to these updated packages, which contain backported patches to correct these issues.

4. Solution:

Before applying this update, make sure all previously-released errata relevant to your system have been applied.

This update is available via the Red Hat Network. Details on how to use the Red Hat Network to apply this update are available at https://access.redhat.com/knowledge/articles/11258

5. Bugs fixed (http://bugzilla.redhat.com/):

910938 - CVE-2013-0287 sssd: simple access provider flaw prevents intended ACL use when client to an AD provider 914671 - pwd_expiration_warning has wrong default for Kerberos

Original Source

Url : https://rhn.redhat.com/errata/RHSA-2013-0663.html

CWE : Common Weakness Enumeration

% Id Name
100 % CWE-264 Permissions, Privileges, and Access Controls

OVAL Definitions

Definition Id: oval:org.mitre.oval:def:20721
 
Oval ID: oval:org.mitre.oval:def:20721
Title: RHSA-2013:0663: sssd security and bug fix update (Moderate)
Description: The Simple Access Provider in System Security Services Daemon (SSSD) 1.9.0 through 1.9.4, when the Active Directory provider is used, does not properly enforce the simple_deny_groups option, which allows remote authenticated users to bypass intended access restrictions.
Family: unix Class: patch
Reference(s): RHSA-2013:0663-01
CESA-2013:0663
CVE-2013-0287
Version: 4
Platform(s): Red Hat Enterprise Linux 6
CentOS Linux 6
Product(s): sssd
Definition Synopsis:
Definition Id: oval:org.mitre.oval:def:24047
 
Oval ID: oval:org.mitre.oval:def:24047
Title: ELSA-2013:0663: sssd security and bug fix update (Moderate)
Description: The Simple Access Provider in System Security Services Daemon (SSSD) 1.9.0 through 1.9.4, when the Active Directory provider is used, does not properly enforce the simple_deny_groups option, which allows remote authenticated users to bypass intended access restrictions.
Family: unix Class: patch
Reference(s): ELSA-2013:0663-01
CVE-2013-0287
Version: 6
Platform(s): Oracle Linux 6
Product(s): sssd
Definition Synopsis:
Definition Id: oval:org.mitre.oval:def:27145
 
Oval ID: oval:org.mitre.oval:def:27145
Title: DEPRECATED: ELSA-2013-0663 -- sssd security and bug fix update (moderate)
Description: [1.9.2-82.4] - Resolves: rhbz#911298 - sssd: simple access provider flaw prevents intended ACL use when client to an AD provider [1.9.2-82.3] - Fix pwd_expiration_warning=0 - Resolves: rhbz#914671 - pwd_expiration_warning has wrong default for Kerberos [1.9.2-82.2] - Resolves: rhbz#914671 - pwd_expiration_warning has wrong default for Kerberos - Fix the NVR [1.9.2-82.1] - Resolves: rhbz#907362 - Serious performance regression in sssd
Family: unix Class: patch
Reference(s): ELSA-2013-0663
CVE-2013-0287
Version: 4
Platform(s): Oracle Linux 6
Product(s): sssd
Definition Synopsis:

CPE : Common Platform Enumeration

TypeDescriptionCount
Application 5

Nessus® Vulnerability Scanner

Date Description
2014-06-13 Name : The remote openSUSE host is missing a security update.
File : openSUSE-2013-264.nasl - Type : ACT_GATHER_INFO
2013-07-12 Name : The remote Oracle Linux host is missing one or more security updates.
File : oraclelinux_ELSA-2013-0663.nasl - Type : ACT_GATHER_INFO
2013-04-01 Name : The remote Fedora host is missing a security update.
File : fedora_2013-4193.nasl - Type : ACT_GATHER_INFO
2013-03-21 Name : The remote CentOS host is missing one or more security updates.
File : centos_RHSA-2013-0663.nasl - Type : ACT_GATHER_INFO
2013-03-20 Name : The remote Red Hat host is missing one or more security updates.
File : redhat-RHSA-2013-0663.nasl - Type : ACT_GATHER_INFO
2013-03-20 Name : The remote Scientific Linux host is missing one or more security updates.
File : sl_20130319_sssd_on_SL6_x.nasl - Type : ACT_GATHER_INFO

Alert History

If you want to see full details history, please login or register.
0
1
2
3
Date Informations
2014-02-17 11:57:03
  • Multiple Updates
2013-03-22 21:19:36
  • Multiple Updates
2013-03-21 21:19:22
  • Multiple Updates
2013-03-19 21:17:31
  • First insertion