CVE-2018-10852

Description

The UNIX pipe which sudo uses to contact SSSD and read the available sudo rules from SSSD has too wide permissions, which means that anyone who can send a message using the same raw protocol that sudo and SSSD use can read the sudo rules available for any user. This affects versions of SSSD before 1.16.3.

Risk Information

Base Score
7.5
MODERATE
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS Score
Exploitation Probability
0.302

Associated Vulnerability

VulnerabilityOS Platform
Sssd security update (CESA-2017:3379) sssd-1.16.2-13.el7.x86_64.rpmLinux
Sssd security update (CESA-2017:3379) sssd-ad-1.16.2-13.el7.x86_64.rpmLinux
Sssd security update (CESA-2017:3379) sssd-ipa-1.16.2-13.el7.x86_64.rpmLinux
Sssd security update (CESA-2017:3379) sssd-kcm-1.16.2-13.el7.x86_64.rpmLinux
Sssd security update (CESA-2017:3379) sssd-dbus-1.16.2-13.el7.x86_64.rpmLinux
Sssd security update (CESA-2017:3379) sssd-krb5-1.16.2-13.el7.x86_64.rpmLinux
Sssd security update (CESA-2017:3379) sssd-ldap-1.16.2-13.el7.x86_64.rpmLinux
Sssd security update (CESA-2017:3379) python-sss-1.16.2-13.el7.x86_64.rpmLinux
Sssd security update (CESA-2017:3379) sssd-proxy-1.16.2-13.el7.x86_64.rpmLinux
Sssd security update (CESA-2017:3379) sssd-tools-1.16.2-13.el7.x86_64.rpmLinux
Sssd security update (CESA-2017:3379) libipa_hbac-1.16.2-13.el7.i686.rpmLinux
Sssd security update (CESA-2017:3379) libipa_hbac-1.16.2-13.el7.x86_64.rpmLinux
Sssd security update (CESA-2017:3379) libsss_sudo-1.16.2-13.el7.x86_64.rpmLinux
Sssd security update (CESA-2017:3379) sssd-client-1.16.2-13.el7.i686.rpmLinux
Sssd security update (CESA-2017:3379) sssd-client-1.16.2-13.el7.x86_64.rpmLinux
Sssd security update (CESA-2017:3379) sssd-common-1.16.2-13.el7.x86_64.rpmLinux
Sssd security update (CESA-2017:3379) libsss_idmap-1.16.2-13.el7.i686.rpmLinux
Sssd security update (CESA-2017:3379) libsss_idmap-1.16.2-13.el7.x86_64.rpmLinux
Sssd security update (CESA-2017:3379) libsss_autofs-1.16.2-13.el7.x86_64.rpmLinux
Sssd security update (CESA-2017:3379) libsss_certmap-1.16.2-13.el7.i686.rpmLinux
Sssd security update (CESA-2017:3379) libsss_certmap-1.16.2-13.el7.x86_64.rpmLinux
Sssd security update (CESA-2017:3379) sssd-common-pac-1.16.2-13.el7.x86_64.rpmLinux
Sssd security update (CESA-2017:3379) libsss_nss_idmap-1.16.2-13.el7.i686.rpmLinux
Sssd security update (CESA-2017:3379) libsss_nss_idmap-1.16.2-13.el7.x86_64.rpmLinux
Sssd security update (CESA-2017:3379) libsss_simpleifp-1.16.2-13.el7.i686.rpmLinux
Sssd security update (CESA-2017:3379) libsss_simpleifp-1.16.2-13.el7.x86_64.rpmLinux
Sssd security update (CESA-2017:3379) sssd-krb5-common-1.16.2-13.el7.x86_64.rpmLinux
Sssd security update (CESA-2017:3379) sssd-libwbclient-1.16.2-13.el7.x86_64.rpmLinux
Sssd security update (CESA-2017:3379) libipa_hbac-devel-1.16.2-13.el7.i686.rpmLinux
Sssd security update (CESA-2017:3379) libipa_hbac-devel-1.16.2-13.el7.x86_64.rpmLinux
Sssd security update (CESA-2017:3379) python-sss-murmur-1.16.2-13.el7.x86_64.rpmLinux
Sssd security update (CESA-2017:3379) python-sssdconfig-1.16.2-13.el7.noarch.rpmLinux
Sssd security update (CESA-2017:3379) sssd-polkit-rules-1.16.2-13.el7.x86_64.rpmLinux
Sssd security update (CESA-2017:3379) libsss_idmap-devel-1.16.2-13.el7.i686.rpmLinux
Sssd security update (CESA-2017:3379) libsss_idmap-devel-1.16.2-13.el7.x86_64.rpmLinux
Sssd security update (CESA-2017:3379) python-libipa_hbac-1.16.2-13.el7.x86_64.rpmLinux
Sssd security update (CESA-2017:3379) sssd-winbind-idmap-1.16.2-13.el7.x86_64.rpmLinux
Sssd security update (CESA-2017:3379) libsss_certmap-devel-1.16.2-13.el7.i686.rpmLinux
Sssd security update (CESA-2017:3379) libsss_certmap-devel-1.16.2-13.el7.x86_64.rpmLinux
Sssd security update (CESA-2017:3379) libsss_nss_idmap-devel-1.16.2-13.el7.i686.rpmLinux
Sssd security update (CESA-2017:3379) libsss_nss_idmap-devel-1.16.2-13.el7.x86_64.rpmLinux
Sssd security update (CESA-2017:3379) libsss_simpleifp-devel-1.16.2-13.el7.i686.rpmLinux
Sssd security update (CESA-2017:3379) libsss_simpleifp-devel-1.16.2-13.el7.x86_64.rpmLinux
Sssd security update (CESA-2017:3379) sssd-libwbclient-devel-1.16.2-13.el7.i686.rpmLinux
Sssd security update (CESA-2017:3379) sssd-libwbclient-devel-1.16.2-13.el7.x86_64.rpmLinux
Sssd security update (CESA-2017:3379) python-libsss_nss_idmap-1.16.2-13.el7.x86_64.rpmLinux
SUSE-SU-2019:0081-1(SUSE Linux Enterprise Desktop 12-SP3 ) libipa_hbac0-1.13.4-34.23.1.x86_64.rpmLinux
SUSE-SU-2019:0081-1(SUSE Linux Enterprise Desktop 12-SP3 ) libipa_hbac0-debuginfo-1.13.4-34.23.1.x86_64.rpmLinux
SUSE-SU-2019:0081-1(SUSE Linux Enterprise Desktop 12-SP3 ) libsss_idmap0-1.13.4-34.23.1.x86_64.rpmLinux
SUSE-SU-2019:0081-1(SUSE Linux Enterprise Desktop 12-SP3 ) libsss_idmap0-debuginfo-1.13.4-34.23.1.x86_64.rpmLinux
SUSE-SU-2019:0081-1(SUSE Linux Enterprise Desktop 12-SP3 ) libsss_nss_idmap0-1.13.4-34.23.1.x86_64.rpmLinux
SUSE-SU-2019:0081-1(SUSE Linux Enterprise Desktop 12-SP3 ) libsss_nss_idmap0-debuginfo-1.13.4-34.23.1.x86_64.rpmLinux
SUSE-SU-2019:0081-1(SUSE Linux Enterprise Desktop 12-SP3 ) libsss_sudo-1.13.4-34.23.1.x86_64.rpmLinux
SUSE-SU-2019:0081-1(SUSE Linux Enterprise Desktop 12-SP3 ) libsss_sudo-debuginfo-1.13.4-34.23.1.x86_64.rpmLinux
SUSE-SU-2019:0081-1(SUSE Linux Enterprise Desktop 12-SP3 ) python-sssd-config-1.13.4-34.23.1.x86_64.rpmLinux
SUSE-SU-2019:0081-1(SUSE Linux Enterprise Desktop 12-SP3 ) python-sssd-config-debuginfo-1.13.4-34.23.1.x86_64.rpmLinux
SUSE-SU-2019:0081-1(SUSE Linux Enterprise Desktop 12-SP3 ) sssd-1.13.4-34.23.1.x86_64.rpmLinux
SUSE-SU-2019:0081-1(SUSE Linux Enterprise Desktop 12-SP3 ) sssd-32bit-1.13.4-34.23.1.x86_64.rpmLinux
SUSE-SU-2019:0081-1(SUSE Linux Enterprise Desktop 12-SP3 ) sssd-ad-1.13.4-34.23.1.x86_64.rpmLinux
SUSE-SU-2019:0081-1(SUSE Linux Enterprise Desktop 12-SP3 ) sssd-ad-debuginfo-1.13.4-34.23.1.x86_64.rpmLinux
SUSE-SU-2019:0081-1(SUSE Linux Enterprise Desktop 12-SP3 ) sssd-debuginfo-1.13.4-34.23.1.x86_64.rpmLinux
SUSE-SU-2019:0081-1(SUSE Linux Enterprise Desktop 12-SP3 ) sssd-debuginfo-32bit-1.13.4-34.23.1.x86_64.rpmLinux
SUSE-SU-2019:0081-1(SUSE Linux Enterprise Desktop 12-SP3 ) sssd-debugsource-1.13.4-34.23.1.x86_64.rpmLinux
SUSE-SU-2019:0081-1(SUSE Linux Enterprise Desktop 12-SP3 ) sssd-ipa-1.13.4-34.23.1.x86_64.rpmLinux
SUSE-SU-2019:0081-1(SUSE Linux Enterprise Desktop 12-SP3 ) sssd-ipa-debuginfo-1.13.4-34.23.1.x86_64.rpmLinux
SUSE-SU-2019:0081-1(SUSE Linux Enterprise Desktop 12-SP3 ) sssd-krb5-1.13.4-34.23.1.x86_64.rpmLinux
SUSE-SU-2019:0081-1(SUSE Linux Enterprise Desktop 12-SP3 ) sssd-krb5-common-1.13.4-34.23.1.x86_64.rpmLinux
SUSE-SU-2019:0081-1(SUSE Linux Enterprise Desktop 12-SP3 ) sssd-krb5-common-debuginfo-1.13.4-34.23.1.x86_64.rpmLinux
SUSE-SU-2019:0081-1(SUSE Linux Enterprise Desktop 12-SP3 ) sssd-krb5-debuginfo-1.13.4-34.23.1.x86_64.rpmLinux
SUSE-SU-2019:0081-1(SUSE Linux Enterprise Desktop 12-SP3 ) sssd-ldap-1.13.4-34.23.1.x86_64.rpmLinux
SUSE-SU-2019:0081-1(SUSE Linux Enterprise Desktop 12-SP3 ) sssd-ldap-debuginfo-1.13.4-34.23.1.x86_64.rpmLinux
SUSE-SU-2019:0081-1(SUSE Linux Enterprise Desktop 12-SP3 ) sssd-proxy-1.13.4-34.23.1.x86_64.rpmLinux
SUSE-SU-2019:0081-1(SUSE Linux Enterprise Desktop 12-SP3 ) sssd-proxy-debuginfo-1.13.4-34.23.1.x86_64.rpmLinux
SUSE-SU-2019:0081-1(SUSE Linux Enterprise Desktop 12-SP3 ) sssd-tools-1.13.4-34.23.1.x86_64.rpmLinux
SUSE-SU-2019:0081-1(SUSE Linux Enterprise Desktop 12-SP3 ) sssd-tools-debuginfo-1.13.4-34.23.1.x86_64.rpmLinux
SUSE-SU-2019:0556-1(SUSE Linux Enterprise Desktop 12-SP4 ) libipa_hbac0-1.16.1-4.3.2.x86_64.rpmLinux
SUSE-SU-2019:0556-1(SUSE Linux Enterprise Desktop 12-SP4 ) libipa_hbac0-debuginfo-1.16.1-4.3.2.x86_64.rpmLinux
SUSE-SU-2019:0556-1(SUSE Linux Enterprise Desktop 12-SP4 ) libsss_certmap0-1.16.1-4.3.2.x86_64.rpmLinux
SUSE-SU-2019:0556-1(SUSE Linux Enterprise Desktop 12-SP4 ) libsss_certmap0-debuginfo-1.16.1-4.3.2.x86_64.rpmLinux
SUSE-SU-2019:0556-1(SUSE Linux Enterprise Desktop 12-SP4 ) libsss_idmap0-1.16.1-4.3.2.x86_64.rpmLinux
SUSE-SU-2019:0556-1(SUSE Linux Enterprise Desktop 12-SP4 ) libsss_idmap0-debuginfo-1.16.1-4.3.2.x86_64.rpmLinux
SUSE-SU-2019:0556-1(SUSE Linux Enterprise Desktop 12-SP4 ) libsss_nss_idmap0-1.16.1-4.3.2.x86_64.rpmLinux
SUSE-SU-2019:0556-1(SUSE Linux Enterprise Desktop 12-SP4 ) libsss_nss_idmap0-debuginfo-1.16.1-4.3.2.x86_64.rpmLinux
SUSE-SU-2019:0556-1(SUSE Linux Enterprise Desktop 12-SP4 ) libsss_simpleifp0-1.16.1-4.3.2.x86_64.rpmLinux
SUSE-SU-2019:0556-1(SUSE Linux Enterprise Desktop 12-SP4 ) libsss_simpleifp0-debuginfo-1.16.1-4.3.2.x86_64.rpmLinux
SUSE-SU-2019:0556-1(SUSE Linux Enterprise Desktop 12-SP4 ) python-sssd-config-1.16.1-4.3.2.x86_64.rpmLinux
SUSE-SU-2019:0556-1(SUSE Linux Enterprise Desktop 12-SP4 ) python-sssd-config-debuginfo-1.16.1-4.3.2.x86_64.rpmLinux
SUSE-SU-2019:0556-1(SUSE Linux Enterprise Desktop 12-SP4 ) sssd-1.16.1-4.3.2.x86_64.rpmLinux
SUSE-SU-2019:0556-1(SUSE Linux Enterprise Desktop 12-SP4 ) sssd-32bit-1.16.1-4.3.2.x86_64.rpmLinux
SUSE-SU-2019:0556-1(SUSE Linux Enterprise Desktop 12-SP4 ) sssd-ad-1.16.1-4.3.2.x86_64.rpmLinux
SUSE-SU-2019:0556-1(SUSE Linux Enterprise Desktop 12-SP4 ) sssd-ad-debuginfo-1.16.1-4.3.2.x86_64.rpmLinux
SUSE-SU-2019:0556-1(SUSE Linux Enterprise Desktop 12-SP4 ) sssd-debuginfo-1.16.1-4.3.2.x86_64.rpmLinux
SUSE-SU-2019:0556-1(SUSE Linux Enterprise Desktop 12-SP4 ) sssd-debuginfo-32bit-1.16.1-4.3.2.x86_64.rpmLinux
SUSE-SU-2019:0556-1(SUSE Linux Enterprise Desktop 12-SP4 ) sssd-debugsource-1.16.1-4.3.2.x86_64.rpmLinux
SUSE-SU-2019:0556-1(SUSE Linux Enterprise Desktop 12-SP4 ) sssd-ipa-1.16.1-4.3.2.x86_64.rpmLinux
SUSE-SU-2019:0556-1(SUSE Linux Enterprise Desktop 12-SP4 ) sssd-ipa-debuginfo-1.16.1-4.3.2.x86_64.rpmLinux
SUSE-SU-2019:0556-1(SUSE Linux Enterprise Desktop 12-SP4 ) sssd-krb5-1.16.1-4.3.2.x86_64.rpmLinux
SUSE-SU-2019:0556-1(SUSE Linux Enterprise Desktop 12-SP4 ) sssd-krb5-common-1.16.1-4.3.2.x86_64.rpmLinux
SUSE-SU-2019:0556-1(SUSE Linux Enterprise Desktop 12-SP4 ) sssd-krb5-common-debuginfo-1.16.1-4.3.2.x86_64.rpmLinux
SUSE-SU-2019:0556-1(SUSE Linux Enterprise Desktop 12-SP4 ) sssd-krb5-debuginfo-1.16.1-4.3.2.x86_64.rpmLinux
SUSE-SU-2019:0556-1(SUSE Linux Enterprise Desktop 12-SP4 ) sssd-ldap-1.16.1-4.3.2.x86_64.rpmLinux
SUSE-SU-2019:0556-1(SUSE Linux Enterprise Desktop 12-SP4 ) sssd-ldap-debuginfo-1.16.1-4.3.2.x86_64.rpmLinux
SUSE-SU-2019:0556-1(SUSE Linux Enterprise Desktop 12-SP4 ) sssd-proxy-1.16.1-4.3.2.x86_64.rpmLinux
SUSE-SU-2019:0556-1(SUSE Linux Enterprise Desktop 12-SP4 ) sssd-proxy-debuginfo-1.16.1-4.3.2.x86_64.rpmLinux
SUSE-SU-2019:0556-1(SUSE Linux Enterprise Desktop 12-SP4 ) sssd-tools-1.16.1-4.3.2.x86_64.rpmLinux
SUSE-SU-2019:0556-1(SUSE Linux Enterprise Desktop 12-SP4 ) sssd-tools-debuginfo-1.16.1-4.3.2.x86_64.rpmLinux
Libipa_hbac update (ELSA-2018-3158) libipa_hbac-1.16.2-13.el7.x86_64.rpmLinux
Libipa_hbac-devel update (ELSA-2018-3158) libipa_hbac-devel-1.16.2-13.el7.x86_64.rpmLinux
Libsss_autofs update (ELSA-2018-3158) libsss_autofs-1.16.2-13.el7.x86_64.rpmLinux
Libsss_certmap update (ELSA-2018-3158) libsss_certmap-1.16.2-13.el7.x86_64.rpmLinux
Libsss_certmap-devel update (ELSA-2018-3158) libsss_certmap-devel-1.16.2-13.el7.x86_64.rpmLinux
Libsss_idmap update (ELSA-2018-3158) libsss_idmap-1.16.2-13.el7.x86_64.rpmLinux
Libsss_idmap-devel update (ELSA-2018-3158) libsss_idmap-devel-1.16.2-13.el7.x86_64.rpmLinux
Libsss_nss_idmap update (ELSA-2018-3158) libsss_nss_idmap-1.16.2-13.el7.x86_64.rpmLinux
Libsss_nss_idmap-devel update (ELSA-2018-3158) libsss_nss_idmap-devel-1.16.2-13.el7.x86_64.rpmLinux
Libsss_simpleifp update (ELSA-2018-3158) libsss_simpleifp-1.16.2-13.el7.x86_64.rpmLinux
Libsss_simpleifp-devel update (ELSA-2018-3158) libsss_simpleifp-devel-1.16.2-13.el7.x86_64.rpmLinux
Libsss_sudo update (ELSA-2018-3158) libsss_sudo-1.16.2-13.el7.x86_64.rpmLinux
Python-libipa_hbac update (ELSA-2018-3158) python-libipa_hbac-1.16.2-13.el7.x86_64.rpmLinux
Python-libsss_nss_idmap update (ELSA-2018-3158) python-libsss_nss_idmap-1.16.2-13.el7.x86_64.rpmLinux
Python-sss update (ELSA-2018-3158) python-sss-1.16.2-13.el7.x86_64.rpmLinux
Python-sss-murmur update (ELSA-2018-3158) python-sss-murmur-1.16.2-13.el7.x86_64.rpmLinux
Sssd update (ELSA-2018-3158) sssd-1.16.2-13.el7.x86_64.rpmLinux
Sssd-ad update (ELSA-2018-3158) sssd-ad-1.16.2-13.el7.x86_64.rpmLinux
Sssd-client update (ELSA-2018-3158) sssd-client-1.16.2-13.el7.x86_64.rpmLinux
Sssd-common update (ELSA-2018-3158) sssd-common-1.16.2-13.el7.x86_64.rpmLinux
Sssd-common-pac update (ELSA-2018-3158) sssd-common-pac-1.16.2-13.el7.x86_64.rpmLinux
Sssd-dbus update (ELSA-2018-3158) sssd-dbus-1.16.2-13.el7.x86_64.rpmLinux
Sssd-ipa update (ELSA-2018-3158) sssd-ipa-1.16.2-13.el7.x86_64.rpmLinux
Sssd-kcm update (ELSA-2018-3158) sssd-kcm-1.16.2-13.el7.x86_64.rpmLinux
Sssd-krb5 update (ELSA-2018-3158) sssd-krb5-1.16.2-13.el7.x86_64.rpmLinux
Sssd-krb5-common update (ELSA-2018-3158) sssd-krb5-common-1.16.2-13.el7.x86_64.rpmLinux
Sssd-ldap update (ELSA-2018-3158) sssd-ldap-1.16.2-13.el7.x86_64.rpmLinux
Sssd-libwbclient update (ELSA-2018-3158) sssd-libwbclient-1.16.2-13.el7.x86_64.rpmLinux
Sssd-libwbclient-devel update (ELSA-2018-3158) sssd-libwbclient-devel-1.16.2-13.el7.x86_64.rpmLinux
Sssd-polkit-rules update (ELSA-2018-3158) sssd-polkit-rules-1.16.2-13.el7.x86_64.rpmLinux
Sssd-proxy update (ELSA-2018-3158) sssd-proxy-1.16.2-13.el7.x86_64.rpmLinux
Sssd-tools update (ELSA-2018-3158) sssd-tools-1.16.2-13.el7.x86_64.rpmLinux
Sssd-winbind-idmap update (ELSA-2018-3158) sssd-winbind-idmap-1.16.2-13.el7.x86_64.rpmLinux
Python-sssdconfig update (ELSA-2018-3158) python-sssdconfig-1.16.2-13.el7.noarch.rpmLinux
Libipa_hbac update (ELSA-2018-3158) libipa_hbac-1.16.2-13.el7.i686.rpmLinux
Libipa_hbac-devel update (ELSA-2018-3158) libipa_hbac-devel-1.16.2-13.el7.i686.rpmLinux
Libsss_certmap update (ELSA-2018-3158) libsss_certmap-1.16.2-13.el7.i686.rpmLinux
Libsss_certmap-devel update (ELSA-2018-3158) libsss_certmap-devel-1.16.2-13.el7.i686.rpmLinux
Libsss_idmap update (ELSA-2018-3158) libsss_idmap-1.16.2-13.el7.i686.rpmLinux
Libsss_idmap-devel update (ELSA-2018-3158) libsss_idmap-devel-1.16.2-13.el7.i686.rpmLinux
Libsss_nss_idmap update (ELSA-2018-3158) libsss_nss_idmap-1.16.2-13.el7.i686.rpmLinux
Libsss_nss_idmap-devel update (ELSA-2018-3158) libsss_nss_idmap-devel-1.16.2-13.el7.i686.rpmLinux
Libsss_simpleifp update (ELSA-2018-3158) libsss_simpleifp-1.16.2-13.el7.i686.rpmLinux
Libsss_simpleifp-devel update (ELSA-2018-3158) libsss_simpleifp-devel-1.16.2-13.el7.i686.rpmLinux
Sssd-client update (ELSA-2018-3158) sssd-client-1.16.2-13.el7.i686.rpmLinux
Sssd-libwbclient-devel update (ELSA-2018-3158) sssd-libwbclient-devel-1.16.2-13.el7.i686.rpmLinux
System Security Services Daemon (USN-5067-1) sssd_2.2.3-3ubuntu0.8_amd64.debLinux
System Security Services Daemon (USN-5067-1) sssd_2.4.0-1ubuntu6.1_amd64.debLinux
System Security Services Daemon (USN-5067-1) sssd_1.16.1-1ubuntu1.8_i386.debLinux
System Security Services Daemon (USN-5067-1) sssd_1.16.1-1ubuntu1.8_amd64.debLinux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234