The System Security Services Daemon (SSSD) 1.11.6 does not properly identify group membership when a non-POSIX group is in a group membership chain, which allows local users to bypass access restrictions via unspecified vectors.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Sssd | Fedoraproject | 1.11.6 (including) | 1.11.6 (including) |
Enterprise_linux | Redhat | 5 (including) | 5 (including) |
Enterprise_linux | Redhat | 6.0 (including) | 6.0 (including) |
Red Hat Enterprise Linux 6 | RedHat | sssd-0:1.11.6-30.el6 | * |
Red Hat Enterprise Linux 7 | RedHat | sssd-0:1.12.2-58.el7 | * |
Sssd | Ubuntu | lucid | * |
Sssd | Ubuntu | precise | * |
Sssd | Ubuntu | saucy | * |
Sssd | Ubuntu | trusty | * |
Sssd | Ubuntu | upstream | * |
Sssd | Ubuntu | utopic | * |