The pam_parse_in_data_v2 function in src/responder/pam/pamsrv_cmd.c in the PAM responder in SSSD 1.5.0, 1.4.x, and 1.3 allows local users to cause a denial of service (infinite loop, crash, and login prevention) via a crafted packet.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Sssd | Fedorahosted | 1.4.0 (including) | 1.4.0 (including) |
Sssd | Fedorahosted | 1.4.1 (including) | 1.4.1 (including) |
Sssd | Fedoraproject | 1.3.0 (including) | 1.3.0 (including) |
Sssd | Fedoraproject | 1.5.0 (including) | 1.5.0 (including) |
Red Hat Enterprise Linux 5 | RedHat | sssd-0:1.5.1-37.el5 | * |
Red Hat Enterprise Linux 6 | RedHat | sssd-0:1.5.1-34.el6 | * |
Sssd | Ubuntu | karmic | * |
Sssd | Ubuntu | maverick | * |
Sssd | Ubuntu | upstream | * |