CVE-2015-5292: Medium severity fedoraproject Sssd vulnerability
A memory leak was found in the sssdpacplugin (sssdpacplugin.so library), which is distributed with the sssdclient package.
Original report with additional details:
https://fedorahosted.org/sssd/ticket/2803
Patch:
https://fedorahosted.org/sssd/attachment/ticket/2803/0001-Fix-memory-leak-in-sssdpacverify.patch
Other sources
Memory leak in the Privilege Attribute Certificate (PAC) responder plugin (sssdpacplugin.so) in System Security Services Daemon (SSSD) 1.10 before 1.13.1 allows remote authenticated users to cause a denial of service (memory consumption) via a large number of logins that trigger parsing of PAC blobs during Kerberos authentication.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-5292?
CVE-2015-5292 has been classified as having a moderate severity due to the potential impact of memory leaks.
How do I fix CVE-2015-5292?
To fix CVE-2015-5292, you should apply the latest patch provided for the affected versions of the sssd_client package.
Which versions of SSSD are affected by CVE-2015-5292?
The affected versions of SSSD include 1.10.0 to 1.13.0, specifically versions 1.10.x, 1.11.x, 1.12.x, and 1.13.0.
What is the impact of CVE-2015-5292?
The impact of CVE-2015-5292 is primarily a memory leak which can lead to exhaustion of resources over time.
Is there a public reference for CVE-2015-5292?
Yes, information about CVE-2015-5292 can be found in the bug tracker on Fedora Hosted.