CVE-2013-0287
Published: 21 March 2013
The Simple Access Provider in System Security Services Daemon (SSSD) 1.9.0 through 1.9.4, when the Active Directory provider is used, does not properly enforce the simple_deny_groups option, which allows remote authenticated users to bypass intended access restrictions.
Notes
Author | Note |
---|---|
jdstrand | per Debian, affects only 1.9 and higher |
Priority
Status
Package | Release | Status |
---|---|---|
sssd Launchpad, Ubuntu, Debian |
hardy |
Does not exist
|
lucid |
Not vulnerable
|
|
oneiric |
Not vulnerable
|
|
precise |
Not vulnerable
|
|
quantal |
Ignored
(end of life)
|
|
raring |
Ignored
(end of life)
|
|
saucy |
Not vulnerable
(1.11.1-0ubuntu1)
|
|
trusty |
Does not exist
(trusty was not-affected [1.11.4-1ubuntu2])
|
|
upstream |
Needs triage
|