The System Security Services Daemon (SSSD) 1.11.6 does not properly identify group membership when a non-POSIX group is in a group membership chain, which allows local users to bypass access restrictions via unspecified vectors.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Sssd | Fedoraproject | 1.11.6 (including) | 1.11.6 (including) |
| Enterprise_linux | Redhat | 5 (including) | 5 (including) |
| Enterprise_linux | Redhat | 6.0 (including) | 6.0 (including) |
| Red Hat Enterprise Linux 6 | RedHat | sssd-0:1.11.6-30.el6 | * |
| Red Hat Enterprise Linux 7 | RedHat | sssd-0:1.12.2-58.el7 | * |
| Sssd | Ubuntu | lucid | * |
| Sssd | Ubuntu | precise | * |
| Sssd | Ubuntu | saucy | * |
| Sssd | Ubuntu | trusty | * |
| Sssd | Ubuntu | upstream | * |
| Sssd | Ubuntu | utopic | * |