Improper access control in System Security Services Daemon (SSSD) - CVE-2019-3811

 

Improper access control in System Security Services Daemon (SSSD) - CVE-2019-3811

Published: January 22, 2019


Vulnerability identifier: #VU17121
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-3811
CWE-ID: CWE-284
Exploitation vector: Adjecent network
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows an adjacent authenticated attacker to bypass security restrictions.

The vulnerability exists due to the return of '/' (the root directory) instead of '' (the empty string / no home directory) if a user was configured with no home directory set. An adjacent attacker can bypass services that restrict the user's filesystem access to within their home directory through chroot().


Affected software

System Security Services Daemon (SSSD)
Amazon Linux AMI
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Scientific Computing
Opensuse
Ubuntu
sssd (Ubuntu package)
Data Computing Appliance (DCA)

How to mitigate CVE-2019-3811

Update to version 2.1.

System Security Services Daemon (SSSD) - update to 2.1.0
sssd (Ubuntu package) - addressed in versions 1.16.1-1ubuntu1.8, 2.2.3-3ubuntu0.7, 2.4.0-1ubuntu6.1
Data Computing Appliance (DCA) - update to 4.3.0.0

External References

Related Security Bulletins