Description
A vulnerability was found in sssd. If a user was configured with no home directory set, sssd would return '/' (the root directory) instead of '' (the empty string / no home directory). This could impact services that restrict the user's filesystem access to within their home directory through chroot() etc. All versions before 2.1 are vulnerable.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-1635-1 | sssd security update |
Debian DLA |
DLA-3436-1 | sssd security update |
EUVD |
EUVD-2019-13434 | A vulnerability was found in sssd. If a user was configured with no home directory set, sssd would return '/' (the root directory) instead of '' (the empty string / no home directory). This could impact services that restrict the user's filesystem access to within their home directory through chroot() etc. All versions before 2.1 are vulnerable. |
Ubuntu USN |
USN-5067-1 | SSSD vulnerabilities |
References
History
No history.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2025-02-13T16:27:24.771Z
Reserved: 2019-01-03T00:00:00.000Z
Link: CVE-2019-3811
No data.
Status : Modified
Published: 2019-01-15T15:29:00.360
Modified: 2024-11-21T04:42:35.407
Link: CVE-2019-3811
OpenCVE Enrichment
No data.
Weaknesses
Debian DLA
EUVD
Ubuntu USN