The (1) sss_autofs_cmd_getautomntent and (2) sss_autofs_cmd_getautomntbyname function in responder/autofs/autofssrv_cmd.c and the (3) ssh_cmd_parse_request function in responder/ssh/sshsrv_cmd.c in System Security Services Daemon (SSSD) before 1.9.4 allow remote attackers to cause a denial of service (out-of-bounds read, crash, and restart) via a crafted SSSD packet.
References
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 01:47
Type | Values Removed | Values Added |
---|---|---|
References | () http://git.fedorahosted.org/cgit/sssd.git/commit/?id=2bd514cfde1938b1e245af11c9b548d58d49b325 - | |
References | () http://git.fedorahosted.org/cgit/sssd.git/commit/?id=30e2585dd46b62aa3a4abdf6de3f40a20e1743ab - | |
References | () http://lists.fedoraproject.org/pipermail/package-announce/2013-February/098434.html - | |
References | () http://lists.fedoraproject.org/pipermail/package-announce/2013-February/098613.html - | |
References | () http://rhn.redhat.com/errata/RHSA-2013-0508.html - | |
References | () http://secunia.com/advisories/51928 - Vendor Advisory | |
References | () http://secunia.com/advisories/52315 - Vendor Advisory | |
References | () http://www.securityfocus.com/bid/57539 - | |
References | () https://bugzilla.redhat.com/show_bug.cgi?id=884601 - | |
References | () https://fedorahosted.org/sssd/ticket/1781 - | |
References | () https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.4 - |
Information
Published : 2013-02-24 19:55
Updated : 2024-11-21 01:47
NVD link : CVE-2013-0220
Mitre link : CVE-2013-0220
CVE.ORG link : CVE-2013-0220
JSON object : View
Products Affected
fedoraproject
- sssd
CWE
CWE-119
Improper Restriction of Operations within the Bounds of a Memory Buffer