CVE-2015-5292

Description

Memory leak in the Privilege Attribute Certificate (PAC) responder plugin (sssd_pac_plugin.so) in System Security Services Daemon (SSSD) 1.10 before 1.13.1 allows remote authenticated users to cause a denial of service (memory consumption) via a large number of logins that trigger parsing of PAC blobs during Kerberos authentication.

Risk Information

Base Score
7.5
MODERATE
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS Score
Exploitation Probability
2.687

Associated Vulnerability

VulnerabilityOS Platform
(RHSA-2015:2355) Low: sssd security, bug fix, and enhancement update sssd-common-1.13.0-40.el7.i686.rpmLinux
(RHSA-2015:2355) Low: sssd security, bug fix, and enhancement update sssd-krb5-common-1.13.0-40.el7.i686.rpmLinux
(RHSA-2015:2355)Low: security, bug fix, and enhancement update libipa_hbac-1.13.0-40.el7.i686.rpmLinux
(RHSA-2015:2355)Low: security, bug fix, and enhancement update libipa_hbac-1.13.0-40.el7.x86_64.rpmLinux
(RHSA-2015:2355)Low: security, bug fix, and enhancement update libipa_hbac-devel-1.13.0-40.el7.i686.rpmLinux
(RHSA-2015:2355)Low: security, bug fix, and enhancement update libipa_hbac-devel-1.13.0-40.el7.x86_64.rpmLinux
(RHSA-2015:2355)Low: security, bug fix, and enhancement update libsss_idmap-1.13.0-40.el7.i686.rpmLinux
(RHSA-2015:2355)Low: security, bug fix, and enhancement update libsss_idmap-1.13.0-40.el7.x86_64.rpmLinux
(RHSA-2015:2355)Low: security, bug fix, and enhancement update libsss_idmap-devel-1.13.0-40.el7.i686.rpmLinux
(RHSA-2015:2355)Low: security, bug fix, and enhancement update libsss_idmap-devel-1.13.0-40.el7.x86_64.rpmLinux
(RHSA-2015:2355)Low: security, bug fix, and enhancement update libsss_nss_idmap-1.13.0-40.el7.i686.rpmLinux
(RHSA-2015:2355)Low: security, bug fix, and enhancement update libsss_nss_idmap-1.13.0-40.el7.x86_64.rpmLinux
(RHSA-2015:2355)Low: security, bug fix, and enhancement update libsss_nss_idmap-devel-1.13.0-40.el7.i686.rpmLinux
(RHSA-2015:2355)Low: security, bug fix, and enhancement update libsss_nss_idmap-devel-1.13.0-40.el7.x86_64.rpmLinux
(RHSA-2015:2355)Low: security, bug fix, and enhancement update libsss_simpleifp-1.13.0-40.el7.i686.rpmLinux
(RHSA-2015:2355)Low: security, bug fix, and enhancement update libsss_simpleifp-1.13.0-40.el7.x86_64.rpmLinux
(RHSA-2015:2355)Low: security, bug fix, and enhancement update libsss_simpleifp-devel-1.13.0-40.el7.i686.rpmLinux
(RHSA-2015:2355)Low: security, bug fix, and enhancement update libsss_simpleifp-devel-1.13.0-40.el7.x86_64.rpmLinux
(RHSA-2015:2355)Low: security, bug fix, and enhancement update python-libipa_hbac-1.13.0-40.el7.x86_64.rpmLinux
(RHSA-2015:2355)Low: security, bug fix, and enhancement update python-libsss_nss_idmap-1.13.0-40.el7.x86_64.rpmLinux
(RHSA-2015:2355)Low: security, bug fix, and enhancement update python-sss-1.13.0-40.el7.x86_64.rpmLinux
(RHSA-2015:2355)Low: security, bug fix, and enhancement update python-sss-murmur-1.13.0-40.el7.x86_64.rpmLinux
(RHSA-2015:2355)Low: security, bug fix, and enhancement update python-sssdconfig-1.13.0-40.el7.noarch.rpmLinux
(RHSA-2015:2355)Low: security, bug fix, and enhancement update sssd-1.13.0-40.el7.x86_64.rpmLinux
(RHSA-2015:2355)Low: security, bug fix, and enhancement update sssd-ad-1.13.0-40.el7.x86_64.rpmLinux
(RHSA-2015:2355)Low: security, bug fix, and enhancement update sssd-client-1.13.0-40.el7.i686.rpmLinux
(RHSA-2015:2355)Low: security, bug fix, and enhancement update sssd-client-1.13.0-40.el7.x86_64.rpmLinux
(RHSA-2015:2355)Low: security, bug fix, and enhancement update sssd-common-1.13.0-40.el7.x86_64.rpmLinux
(RHSA-2015:2355)Low: security, bug fix, and enhancement update sssd-common-pac-1.13.0-40.el7.x86_64.rpmLinux
(RHSA-2015:2355)Low: security, bug fix, and enhancement update sssd-dbus-1.13.0-40.el7.x86_64.rpmLinux
(RHSA-2015:2355)Low: security, bug fix, and enhancement update sssd-debuginfo-1.13.0-40.el7.i686.rpmLinux
(RHSA-2015:2355)Low: security, bug fix, and enhancement update sssd-debuginfo-1.13.0-40.el7.x86_64.rpmLinux
(RHSA-2015:2355)Low: security, bug fix, and enhancement update sssd-ipa-1.13.0-40.el7.x86_64.rpmLinux
(RHSA-2015:2355)Low: security, bug fix, and enhancement update sssd-krb5-1.13.0-40.el7.x86_64.rpmLinux
(RHSA-2015:2355)Low: security, bug fix, and enhancement update sssd-krb5-common-1.13.0-40.el7.x86_64.rpmLinux
(RHSA-2015:2355)Low: security, bug fix, and enhancement update sssd-ldap-1.13.0-40.el7.x86_64.rpmLinux
(RHSA-2015:2355)Low: security, bug fix, and enhancement update sssd-libwbclient-1.13.0-40.el7.x86_64.rpmLinux
(RHSA-2015:2355)Low: security, bug fix, and enhancement update sssd-libwbclient-devel-1.13.0-40.el7.i686.rpmLinux
(RHSA-2015:2355)Low: security, bug fix, and enhancement update sssd-libwbclient-devel-1.13.0-40.el7.x86_64.rpmLinux
(RHSA-2015:2355)Low: security, bug fix, and enhancement update sssd-proxy-1.13.0-40.el7.x86_64.rpmLinux
(RHSA-2015:2355)Low: security, bug fix, and enhancement update sssd-tools-1.13.0-40.el7.x86_64.rpmLinux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234