Bug 801036 (CVE-2013-0219) - VUL-1: CVE-2013-0219 CVE-2013-0220: sssd: Two security issues in sssd-1.9.2
Summary: VUL-1: CVE-2013-0219 CVE-2013-0220: sssd: Two security issues in sssd-1.9.2
Status: RESOLVED FIXED
Alias: CVE-2013-0219
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P3 - Medium : Normal
Target Milestone: ---
Assignee: Howard Guo
QA Contact: Security Team bot
URL:
Whiteboard: CVSSv2:NVD:CVE-2013-0219:3.7:(AV:L/AC...
Keywords:
Depends on:
Blocks:
 
Reported: 2013-01-29 14:11 UTC by Ralf Haferkamp
Modified: 2019-11-06 13:07 UTC (History)
7 users (show)

See Also:
Found By: Other
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Ralf Haferkamp 2013-01-29 14:11:49 UTC
sssd upstream just released version 1.9.4 which is mostly a bug fix release and  contains fixes to security problems that our current package in SP3 suffers from as well. From the changelog:

* A security bug assigned CVE-2013-0219 was fixed - TOCTOU race conditions when creating or removing home directories for users in local domain
* A security bug assigned CVE-2013-0220 was fixed - out-of-bounds reads in autofs and ssh responder

Other than that it also fixes a memory leak in the nss resonder and an issue in the sudo backend (Fate#314543), which affect our packages as well.
Comment 5 Matthias Weckbecker 2013-01-30 14:25:03 UTC
I think it was publicly posted 20130123 according to Red Hat's BZ.
Comment 6 Marcus Meissner 2013-02-20 16:49:24 UTC
CVE-2013-0219

This affects all our currently shipping sssd releases.... 
It is however a minor issue.



CVE-2013-0220
affects the ssh and autofs responders, which only existed beginning with SLES 11 SP3 or later and openSUSE 12.3 or later.
Older versions are not affected.


Minor issue only -> planned update list.
Comment 7 Ralf Haferkamp 2013-10-21 08:27:54 UTC
Reassigning to new sssd maintainer. And closing this bug as it is handled by the planned update list for SLE11-SP2. (Factory and SLE11-SP3 are no longer affected as they ship newer sssd releases)
Comment 8 Victor Pereira 2016-10-19 11:07:32 UTC
the issue still open since no update was released for it.
Comment 9 Howard Guo 2016-10-19 13:36:39 UTC
Good news - none of the distributions under active maintenance are affected by the two CVEs. Both SLES 11 SP3 and SP4 are shipping SSSD v1.9.4 which already has the CVEs addressed.
Comment 10 Johannes Segitz 2017-08-03 14:21:47 UTC
openSUSE Leap and Factory also have fixed versions
Comment 11 Bernhard Wiedemann 2017-12-01 15:41:30 UTC
This is an autogenerated message for OBS integration:
This bug (801036) was mentioned in
https://build.opensuse.org/request/show/547139 Factory / sssd