SB2019101003 - Amazon Linux AMI update for sssd



SB2019101003 - Amazon Linux AMI update for sssd

Published: October 10, 2019 Updated: May 9, 2023

Security Bulletin ID SB2019101003
Severity
Low
Patch available
YES
Number of vulnerabilities 2
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 2 secuirty vulnerabilities.


1) Improper access control (CVE-ID: CVE-2019-3811)

The vulnerability allows an adjacent authenticated attacker to bypass security restrictions.

The vulnerability exists due to the return of '/' (the root directory) instead of '' (the empty string / no home directory) if a user was configured with no home directory set. An adjacent attacker can bypass services that restrict the user's filesystem access to within their home directory through chroot().


2) Security restrictions bypass (CVE-ID: CVE-2018-16838)

The vulnerability allows a remote authenticated attacker to bypass security restrictions on the system.

The vulnerability exists due to a flaw in sssd Group Policy Objects implementation when the GPO is not readable by SSSD due to a too strict permission settings on the server side. A remote attacker can bypass security restrictions.


Remediation

Install update from vendor's website.