CVE Vulnerabilities

CVE-2010-4341

Published: Jan 25, 2011 | Modified: Aug 17, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
2.1 LOW
AV:L/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
2.1 LOW
AV:L/AC:L/Au:N/C:N/I:N/A:P
RedHat/V3
Ubuntu
LOW

The pam_parse_in_data_v2 function in src/responder/pam/pamsrv_cmd.c in the PAM responder in SSSD 1.5.0, 1.4.x, and 1.3 allows local users to cause a denial of service (infinite loop, crash, and login prevention) via a crafted packet.

Affected Software

Name Vendor Start Version End Version
Sssd Fedorahosted 1.4.0 (including) 1.4.0 (including)
Sssd Fedorahosted 1.4.1 (including) 1.4.1 (including)
Sssd Fedoraproject 1.3.0 (including) 1.3.0 (including)
Sssd Fedoraproject 1.5.0 (including) 1.5.0 (including)
Red Hat Enterprise Linux 5 RedHat sssd-0:1.5.1-37.el5 *
Red Hat Enterprise Linux 6 RedHat sssd-0:1.5.1-34.el6 *
Sssd Ubuntu karmic *
Sssd Ubuntu maverick *
Sssd Ubuntu upstream *

References