CVE-2019-3811: Infoleak
A vulnerability was found in sssd where, if a user was configured with no home directory set, sssd would return '/' (the root directory) instead of '' (the empty string / no home directory). This could impact services that restrict the user's filesystem access to within their home directory through chroot().
Other sources
A vulnerability was found in sssd. If a user was configured with no home directory set, sssd would return '/' (the root directory) instead of '' (the empty string / no home directory). This could impact services that restrict the user's filesystem access to within their home directory through chroot() etc. All versions before 2.1 are vulnerable.
An issue was found in SSSD. The default option for fallbackhomedir returns '/' for empty home directories in the passwd file.
References: https://github.com/SSSD/sssd/pull/703
Upstream Patch: https://github.com/SSSD/sssd/pull/703/commits/fa0a6400ebd2f4056a057914355ec2ddefc14fe6 https://github.com/SSSD/sssd/pull/703/commits/fe11bd0d5b7dea9f1723c5a59ba0c47641802797
— Red Hat
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID for this sssd vulnerability?
The vulnerability ID for this sssd vulnerability is CVE-2019-3811.
What is the severity level of CVE-2019-3811?
The severity level of CVE-2019-3811 is medium with a score of 5.2.
How does this vulnerability affect sssd?
This vulnerability in sssd affects users who are configured with no home directory set.
Is there a fix available for CVE-2019-3811?
Yes, there is a fix available for CVE-2019-3811. It is recommended to update to version 1.16.4-21.el7 or later.
Where can I find more information about this vulnerability?
You can find more information about this vulnerability in the sssd GitHub repository and on the CVE-2019-3811 page.