Information disclosure in System Security Services Daemon (SSSD) - CVE-2018-10852

 

Information disclosure in System Security Services Daemon (SSSD) - CVE-2018-10852

Published: August 10, 2018 / Updated: August 13, 2018


Vulnerability identifier: #VU14328
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-10852
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to obtain potentially sensitive information.

The vulnerability exists due to too wide permissions in the UNIX pipe which sudo uses to contact SSSD and read the available sudo rules from SSSD. A remote attacker can send a message using the same raw protocol that sudo and SSSD use can read the sudo rules available for any user.


Affected software

System Security Services Daemon (SSSD)
Amazon Linux AMI
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for Power
Opensuse
Ubuntu
sssd (Ubuntu package)

How to mitigate CVE-2018-10852

Update to version 1.16.3.

System Security Services Daemon (SSSD) - update to 1.16.3
sssd (Ubuntu package) - addressed in versions 1.16.1-1ubuntu1.8, 2.2.3-3ubuntu0.7, 2.4.0-1ubuntu6.1

External References

Related Security Bulletins