MGASA-2018-0350

Source
https://advisories.mageia.org/MGASA-2018-0350.html
Import Source
https://advisories.mageia.org/MGASA-2018-0350.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2018-0350
Related
Published
2018-08-23T23:35:07Z
Modified
2018-08-23T23:09:32Z
Summary
Updated sssd packages fix security vulnerability
Details

Updated sssd packages fix security vulnerability:

The UNIX socket that is used for communication between the sudo utility and the sssd-sudo responder had its permissions set to world-readable and writable, which means that anyone who can send a message using the same raw protocol that sudo and SSSD use can read the sudo rules available for any user (CVE-2018-10852).

References
Credits

Affected packages

Mageia:6 / sssd

Package

Name
sssd
Purl
pkg:rpm/mageia/sssd?distro=mageia-6

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.13.4-9.2.mga6

Ecosystem specific

{
    "section": "core"
}