The pam_parse_in_data_v2 function in src/responder/pam/pamsrv_cmd.c in the PAM responder in SSSD 1.5.0, 1.4.x, and 1.3 allows local users to cause a denial of service (infinite loop, crash, and login prevention) via a crafted packet.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Sssd | Fedorahosted | 1.4.0 (including) | 1.4.0 (including) |
| Sssd | Fedorahosted | 1.4.1 (including) | 1.4.1 (including) |
| Sssd | Fedoraproject | 1.3.0 (including) | 1.3.0 (including) |
| Sssd | Fedoraproject | 1.5.0 (including) | 1.5.0 (including) |
| Red Hat Enterprise Linux 5 | RedHat | sssd-0:1.5.1-37.el5 | * |
| Red Hat Enterprise Linux 6 | RedHat | sssd-0:1.5.1-34.el6 | * |
| Sssd | Ubuntu | karmic | * |
| Sssd | Ubuntu | maverick | * |
| Sssd | Ubuntu | upstream | * |