Information disclosure in System Security Services Daemon (SSSD) - CVE-2018-10852
Published: August 10, 2018 / Updated: August 13, 2018
Vulnerability details
The vulnerability allows a remote attacker to obtain potentially sensitive information.
The vulnerability exists due to too wide permissions in the UNIX pipe which sudo uses to contact SSSD and read the available sudo rules from SSSD. A remote attacker can send a message using the same raw protocol that sudo and SSSD use can read the sudo rules available for any user.
Affected software
Amazon Linux AMI
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for Power
Opensuse
Ubuntu
sssd (Ubuntu package)
How to mitigate CVE-2018-10852
sssd (Ubuntu package) - addressed in versions 1.16.1-1ubuntu1.8, 2.2.3-3ubuntu0.7, 2.4.0-1ubuntu6.1