A vulnerability was found in sssd. If a user was configured with no home directory set, sssd would return / (the root directory) instead of (the empty string / no home directory). This could impact services that restrict the users filesystem access to within their home directory through chroot() etc. All versions before 2.1 are vulnerable.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Sssd | Fedoraproject | * | 2.1 (excluding) |
Red Hat Enterprise Linux 7 | RedHat | sssd-0:1.16.4-21.el7 | * |
Sssd | Ubuntu | bionic | * |
Sssd | Ubuntu | cosmic | * |
Sssd | Ubuntu | disco | * |
Sssd | Ubuntu | esm-infra/xenial | * |
Sssd | Ubuntu | trusty | * |
Sssd | Ubuntu | upstream | * |
Sssd | Ubuntu | xenial | * |