CVE-2019-3811

Published: 15 January 2019

A vulnerability was found in sssd. If a user was configured with no home directory set, sssd would return '/' (the root directory) instead of '' (the empty string / no home directory). This could impact services that restrict the user's filesystem access to within their home directory through chroot() etc. All versions before 2.1 are vulnerable.

Priority

Low

CVSS 3 base score: 5.2

Status

Package Release Status
sssd
Launchpad, Ubuntu, Debian
Upstream
Released (2.2.0-1)
Ubuntu 21.04 (Hirsute Hippo) Not vulnerable
(2.2.2-1)
Ubuntu 20.04 LTS (Focal Fossa) Not vulnerable
(2.2.2-1)
Ubuntu 18.04 LTS (Bionic Beaver)
Released (1.16.1-1ubuntu1.8)
Ubuntu 16.04 ESM (Xenial Xerus) Needed

Ubuntu 14.04 ESM (Trusty Tahr) Does not exist
(trusty was needed)
Patches:
Upstream: https://github.com/SSSD/sssd/commit/28792523a01a7d21bcc8931794164f253e691a68