Your submission was sent successfully! Close

CVE-2019-3811

Published: 15 January 2019

A vulnerability was found in sssd. If a user was configured with no home directory set, sssd would return '/' (the root directory) instead of '' (the empty string / no home directory). This could impact services that restrict the user's filesystem access to within their home directory through chroot() etc. All versions before 2.1 are vulnerable.

Priority

Low

CVSS 3 base score: 5.2

Status

Package Release Status
sssd
Launchpad, Ubuntu, Debian
bionic
Released (1.16.1-1ubuntu1.8)
cosmic Ignored
(reached end-of-life)
disco Ignored
(reached end-of-life)
eoan Not vulnerable
(2.2.0-4ubuntu1)
focal Not vulnerable
(2.2.2-1)
groovy Not vulnerable
(2.2.2-1)
hirsute Not vulnerable
(2.2.2-1)
impish Not vulnerable
(2.2.2-1)
jammy Not vulnerable
(2.2.2-1)
precise Does not exist

trusty Does not exist
(trusty was needed)
upstream
Released (2.2.0-1)
xenial Needed

Patches:
upstream: https://github.com/SSSD/sssd/commit/28792523a01a7d21bcc8931794164f253e691a68