CVE-2018-16883: Infoleak
Published Dec 19, 2018
·Updated
sssd versions from 1.13.0 to before 2.0.0 did not properly restrict access to the infopipe according to the "alloweduids" configuration parameter. If sensitive information were stored in the user directory, this could be inadvertently disclosed to local attackers.
Affected Software
1 affected component
fedoraproject Sssd>=1.13.0<2.0.0
Event History
Dec 19, 2018
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2018-16883.
2
What is the severity of CVE-2018-16883?
The severity of CVE-2018-16883 is medium with a severity value of 5.5.
3
Which software versions are affected by CVE-2018-16883?
sssd versions from 1.13.0 to before 2.0.0 are affected by CVE-2018-16883.
4
What is the impact of CVE-2018-16883?
If sensitive information were stored in the user directory, it could be inadvertently disclosed to local attackers.
5
How can I fix CVE-2018-16883?
To fix CVE-2018-16883, update sssd to version 2.0.0 or later.