Bug 948819 (CVE-2015-5292) - VUL-1: CVE-2015-5292: sssd: memory leak in the sssd_pac_plugin
Summary: VUL-1: CVE-2015-5292: sssd: memory leak in the sssd_pac_plugin
Status: RESOLVED INVALID
Alias: CVE-2015-5292
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P5 - None : Minor
Target Milestone: ---
Assignee: Peter Varkoly
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/157292/
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2015-10-05 12:30 UTC by Andreas Stieger
Modified: 2015-10-05 12:30 UTC (History)
1 user (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Andreas Stieger 2015-10-05 12:30:12 UTC
A memory leak was found in the sssd_pac_plugin (sssd_pac_plugin.so library), which is distributed with the sssd_client package.

Original report with additional details:

https://fedorahosted.org/sssd/ticket/2803

Patch:

https://fedorahosted.org/sssd/attachment/ticket/2803/0001-Fix-memory-leak-in-sssdpac_verify.patch


References:
https://bugzilla.redhat.com/show_bug.cgi?id=1267580
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2015-5292
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-5292
Comment 1 Andreas Stieger 2015-10-05 12:30:41 UTC
The relevant build-time option is:
--enable-pac-responder

openSUSE 13.2: disabled
openSUSE 13.1: not built

SLE 12: disabled
SLE 11: not built