Thursday, November 4, 2021

Huawei EulerOS: CVE-2021-3621: sssd security update

Description
A flaw was found in SSSD, where the sssctl command was vulnerable to shell command injection via the logs-fetch and cache-expire subcommands. This flaw allows an attacker to trick the root user into running a specially crafted sssctl command, such as via sudo, to gain root access. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.
Solution(s)
  • huawei-euleros-2_0_sp8-upgrade-libipa_hbac
  • huawei-euleros-2_0_sp8-upgrade-libsss_autofs
  • huawei-euleros-2_0_sp8-upgrade-libsss_certmap
  • huawei-euleros-2_0_sp8-upgrade-libsss_idmap
  • huawei-euleros-2_0_sp8-upgrade-libsss_nss_idmap
  • huawei-euleros-2_0_sp8-upgrade-libsss_simpleifp
  • huawei-euleros-2_0_sp8-upgrade-libsss_sudo
  • huawei-euleros-2_0_sp8-upgrade-python2-libipa_hbac
  • huawei-euleros-2_0_sp8-upgrade-python2-libsss_nss_idmap
  • huawei-euleros-2_0_sp8-upgrade-python2-sss
  • huawei-euleros-2_0_sp8-upgrade-python2-sss-murmur
  • huawei-euleros-2_0_sp8-upgrade-python2-sssdconfig
  • huawei-euleros-2_0_sp8-upgrade-python3-libipa_hbac
  • huawei-euleros-2_0_sp8-upgrade-python3-libsss_nss_idmap
  • huawei-euleros-2_0_sp8-upgrade-python3-sss
  • huawei-euleros-2_0_sp8-upgrade-python3-sss-murmur
  • huawei-euleros-2_0_sp8-upgrade-python3-sssdconfig
  • huawei-euleros-2_0_sp8-upgrade-sssd
  • huawei-euleros-2_0_sp8-upgrade-sssd-ad
  • huawei-euleros-2_0_sp8-upgrade-sssd-client
  • huawei-euleros-2_0_sp8-upgrade-sssd-common
  • huawei-euleros-2_0_sp8-upgrade-sssd-common-pac
  • huawei-euleros-2_0_sp8-upgrade-sssd-dbus
  • huawei-euleros-2_0_sp8-upgrade-sssd-ipa
  • huawei-euleros-2_0_sp8-upgrade-sssd-kcm
  • huawei-euleros-2_0_sp8-upgrade-sssd-krb5
  • huawei-euleros-2_0_sp8-upgrade-sssd-krb5-common
  • huawei-euleros-2_0_sp8-upgrade-sssd-ldap
  • huawei-euleros-2_0_sp8-upgrade-sssd-libwbclient
  • huawei-euleros-2_0_sp8-upgrade-sssd-nfs-idmap
  • huawei-euleros-2_0_sp8-upgrade-sssd-proxy
  • huawei-euleros-2_0_sp8-upgrade-sssd-tools
  • huawei-euleros-2_0_sp8-upgrade-sssd-winbind-idmap


  • References
  • https://attackerkb.com/topics/cve-2021-3621
  • CVE - 2021-3621
  • EulerOS-SA-2021-2646




  •  

    Copyright © 2021 Vulnerability Database | Cyber Details™

    thank you Templateism for the design - You should have written the code a little more complicated - Nothing Encrypted anymore