USN-6156-1: SSSD vulnerability
12 June 2023
SSSD could allow unintended access to network services.
Releases
Packages
- sssd - System Security Services Daemon
Details
It was discovered that SSSD incorrrectly sanitized certificate data used in
LDAP filters. When using this issue in combination with FreeIPA, a remote
attacker could possibly use this issue to escalate privileges.
Update instructions
The problem can be corrected by updating your system to the following package versions:
Ubuntu 20.04
In general, a standard system update will make all the necessary changes.