CVE-2013-0219
published 2013-02-24CVE-2013-0219: System Security Services Daemon (SSSD) before 1.9.4, when (1) creating, (2) copying, or (3) removing a user home directory tree, allows local users to create…
PriorityP413low3.7CVSS 2.0
AVLACHAuNCPIPAP
EPSS
0.37%
28.9th percentile
System Security Services Daemon (SSSD) before 1.9.4, when (1) creating, (2) copying, or (3) removing a user home directory tree, allows local users to create, modify, or delete arbitrary files via a symlink attack on another user's files.
Affected
80 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | sssd | < sssd 1.8.4-2 (bookworm) | sssd 1.8.4-2 (bookworm) |
| fedoraproject | sssd | <= 1.9.3 | — |
| fedoraproject | sssd | — | — |
| fedoraproject | sssd | — | — |
| fedoraproject | sssd | — | — |
| fedoraproject | sssd | — | — |
| fedoraproject | sssd | — | — |
| fedoraproject | sssd | — | — |
| fedoraproject | sssd | — | — |
| fedoraproject | sssd | — | — |
| fedoraproject | sssd | — | — |
| fedoraproject | sssd | — | — |
| fedoraproject | sssd | — | — |
| fedoraproject | sssd | — | — |
| fedoraproject | sssd | — | — |
| fedoraproject | sssd | — | — |
| fedoraproject | sssd | — | — |
| fedoraproject | sssd | — | — |
| fedoraproject | sssd | — | — |
| fedoraproject | sssd | — | — |
| fedoraproject | sssd | — | — |
| fedoraproject | sssd | — | — |
| fedoraproject | sssd | — | — |
| fedoraproject | sssd | — | — |
| fedoraproject | sssd | — | — |
CVSS provenance
nvdv2.03.7LOWAV:L/AC:H/Au:N/C:P/I:P/A:P
osv3.7LOW
vendor_debian3.7LOW
vendor_redhat3.7LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-6mv3-cv86-5f7j: System Security Services Daemon (SSSD) before 1
ghsa_unreviewed·2022-05-05
CVE-2013-0219 [LOW] GHSA-6mv3-cv86-5f7j: System Security Services Daemon (SSSD) before 1
System Security Services Daemon (SSSD) before 1.9.4, when (1) creating, (2) copying, or (3) removing a user home directory tree, allows local users to create, modify, or delete arbitrary files via a symlink attack on another user's files.
OSV
CVE-2013-0219: System Security Services Daemon (SSSD) before 1
osv·2013-02-24·CVSS 3.7
CVE-2013-0219 [LOW] CVE-2013-0219: System Security Services Daemon (SSSD) before 1
System Security Services Daemon (SSSD) before 1.9.4, when (1) creating, (2) copying, or (3) removing a user home directory tree, allows local users to create, modify, or delete arbitrary files via a symlink attack on another user's files.
Red Hat
sssd: TOCTOU race conditions by copying and removing directory trees
vendor_redhat·2013-01-23·CVSS 3.7
CVE-2013-0219 [LOW] CWE-367 sssd: TOCTOU race conditions by copying and removing directory trees
sssd: TOCTOU race conditions by copying and removing directory trees
System Security Services Daemon (SSSD) before 1.9.4, when (1) creating, (2) copying, or (3) removing a user home directory tree, allows local users to create, modify, or delete arbitrary files via a symlink attack on another user's files.
Debian
CVE-2013-0219: sssd - System Security Services Daemon (SSSD) before 1.9.4, when (1) creating, (2) copy...
vendor_debian·2013·CVSS 3.7
CVE-2013-0219 [LOW] CVE-2013-0219: sssd - System Security Services Daemon (SSSD) before 1.9.4, when (1) creating, (2) copy...
System Security Services Daemon (SSSD) before 1.9.4, when (1) creating, (2) copying, or (3) removing a user home directory tree, allows local users to create, modify, or delete arbitrary files via a symlink attack on another user's files.
Scope: local
bookworm: resolved (fixed in 1.8.4-2)
bullseye: resolved (fixed in 1.8.4-2)
forky: resolved (fixed in 1.8.4-2)
sid: resolved (fixed in 1.8.4-2)
trixie: resolved (fixed in 1.8.4-2)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-0220 CVE-2013-0219 sssd various flaws [fedora-all]
bugzilla·2013-01-23·CVSS 3.7
CVE-2013-0220 [LOW] CVE-2013-0220 CVE-2013-0219 sssd various flaws [fedora-all]
CVE-2013-0220 CVE-2013-0219 sssd various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please note: this issue affects multiple supp
Bugzilla
CVE-2013-0219 sssd: TOCTOU race conditions by copying and removing directory trees [epel-5]
bugzilla·2013-01-23·CVSS 3.7
CVE-2013-0219 [LOW] CVE-2013-0219 sssd: TOCTOU race conditions by copying and removing directory trees [epel-5]
CVE-2013-0219 sssd: TOCTOU race conditions by copying and removing directory trees [epel-5]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
epel-5 t
Bugzilla
CVE-2012-1702 mysql: unspecified unauthenticated DoS vulnerability related to Server (CPU Jan 2013)
bugzilla·2013-01-16·CVSS 5.0
CVE-2012-1702 [MEDIUM] CVE-2012-1702 mysql: unspecified unauthenticated DoS vulnerability related to Server (CPU Jan 2013)
CVE-2012-1702 mysql: unspecified unauthenticated DoS vulnerability related to Server (CPU Jan 2013)
An unspecified vulnerability in the server subcomponent of the MySQL protocol component of the Oracle MySQL server allows remote attackers to alter availability via unspecified vectors.
References:
[1] http://www.oracle.com/technetwork/topics/security/cpujan2013-1515902.html
Discussion:
This issue affects the version of the mysql package, as shipped with Red Hat Enterprise Linux 6.
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 6
Via RHSA-2013:0219 https://rhn.redhat.com/errata/RHSA-2013-0219.html
Bugzilla
CVE-2013-0375 mysql: Unspecified vulnerability in the server replication of the Oracle MySQL server allows remote attackers to alter confidentiality and integrity
bugzilla·2013-01-16·CVSS 5.4
CVE-2013-0375 [MEDIUM] CVE-2013-0375 mysql: Unspecified vulnerability in the server replication of the Oracle MySQL server allows remote attackers to alter confidentiality and integrity
CVE-2013-0375 mysql: Unspecified vulnerability in the server replication of the Oracle MySQL server allows remote attackers to alter confidentiality and integrity
An unspecified vulnerability in the server replication subcomponent of the MySQL protocol component of the Oracle MySQL server allows remote authenticated attackers to alter confidentiality and integrity via unspecified vectors.
References:
[1] http://www.oracle.com/technetwork/topics/security/cpujan2013-1515902.html
Discussion:
This issue affects the version of the mysql package, as shipped with Red Hat Enterprise Linux 6.
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 6
Via RHSA-2013:0219 https://rhn.redhat.com/errata/RHSA-2013-0219.html
Bugzilla
CVE-2013-0389 mysql: unspecified DoS vulnerability related to Server Optimizer (CPU Jan 2013)
bugzilla·2013-01-16·CVSS 6.8
CVE-2013-0389 [MEDIUM] CVE-2013-0389 mysql: unspecified DoS vulnerability related to Server Optimizer (CPU Jan 2013)
CVE-2013-0389 mysql: unspecified DoS vulnerability related to Server Optimizer (CPU Jan 2013)
An unspecified vulnerability in the server optimizer subcomponent of the MySQL protocol component of the Oracle MySQL server allows remote authenticated attackers to alter availability via unspecified vectors.
References:
[1] http://www.oracle.com/technetwork/topics/security/cpujan2013-1515902.html
Discussion:
This issue affects the version of the mysql package, as shipped with Red Hat Enterprise Linux 6.
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 6
Via RHSA-2013:0219 https://rhn.redhat.com/errata/RHSA-2013-0219.html
Bugzilla
CVE-2012-0574 mysql: unspecified DoS vulnerability related to Server (CPU Jan 2013)
bugzilla·2013-01-16·CVSS 4.0
CVE-2012-0574 [MEDIUM] CVE-2012-0574 mysql: unspecified DoS vulnerability related to Server (CPU Jan 2013)
CVE-2012-0574 mysql: unspecified DoS vulnerability related to Server (CPU Jan 2013)
An unspecified vulnerability in the server subcomponent of the MySQL protocol component of the Oracle MySQL server allows remote authenticated attackers to alter availability via unspecified vectors.
References:
[1] http://www.oracle.com/technetwork/topics/security/cpujan2013-1515902.html
Discussion:
This issue affects the version of the mysql package, as shipped with Red Hat Enterprise Linux 6.
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 6
Via RHSA-2013:0219 https://rhn.redhat.com/errata/RHSA-2013-0219.html
Bugzilla
CVE-2013-0383 mysql: unspecified unauthenticated DoS vulnerability related to Server Locking (CPU Jan 2013)
bugzilla·2013-01-16·CVSS 4.3
CVE-2013-0383 [MEDIUM] CVE-2013-0383 mysql: unspecified unauthenticated DoS vulnerability related to Server Locking (CPU Jan 2013)
CVE-2013-0383 mysql: unspecified unauthenticated DoS vulnerability related to Server Locking (CPU Jan 2013)
An unspecified vulnerability in the server locking subcomponent of the MySQL protocol component of the Oracle MySQL server allows remote attackers to alter availability via unspecified vectors.
References:
[1] http://www.oracle.com/technetwork/topics/security/cpujan2013-1515902.html
Discussion:
This issue affects the version of the mysql package, as shipped with Red Hat Enterprise Linux 6.
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 6
Via RHSA-2013:0219 https://rhn.redhat.com/errata/RHSA-2013-0219.html
Bugzilla
CVE-2013-0385 mysql: Unspecified vulnerability in the server replication of the Oracle MySQL server allows local attackers to alter confidentiality and integrity
bugzilla·2013-01-16·CVSS 6.6
CVE-2013-0385 [MEDIUM] CVE-2013-0385 mysql: Unspecified vulnerability in the server replication of the Oracle MySQL server allows local attackers to alter confidentiality and integrity
CVE-2013-0385 mysql: Unspecified vulnerability in the server replication of the Oracle MySQL server allows local attackers to alter confidentiality and integrity
An unspecified vulnerability in the server replication subcomponent of the MySQL protocol component of the Oracle MySQL server allows local attackers to alter confidentiality and integrity via unspecified vectors.
References:
[1] http://www.oracle.com/technetwork/topics/security/cpujan2013-1515902.html
Discussion:
This issue affects the version of the mysql package, as shipped with Red Hat Enterprise Linux 6.
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 6
Via RHSA-2013:0219 https://rhn.redhat.com/errata/RHSA-2013-0219.html
Bugzilla
CVE-2013-0384 mysql: unspecified DoS vulnerability related to Information Schema (CPU Jan 2013)
bugzilla·2013-01-16·CVSS 6.8
CVE-2013-0384 [MEDIUM] CVE-2013-0384 mysql: unspecified DoS vulnerability related to Information Schema (CPU Jan 2013)
CVE-2013-0384 mysql: unspecified DoS vulnerability related to Information Schema (CPU Jan 2013)
An unspecified vulnerability in the information schema subcomponent of the MySQL protocol component of the Oracle MySQL server allows remote authenticated attackers to alter availability via unspecified vectors.
References:
[1] http://www.oracle.com/technetwork/topics/security/cpujan2013-1515902.html
Discussion:
This issue affects the version of the mysql package, as shipped with Red Hat Enterprise Linux 6.
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 6
Via RHSA-2013:0219 https://rhn.redhat.com/errata/RHSA-2013-0219.html
Bugzilla
CVE-2012-1705 mysql: unspecified DoS vulnerability related to Server Optimizer (CPU Jan 2013)
bugzilla·2013-01-16·CVSS 4.0
CVE-2012-1705 [MEDIUM] CVE-2012-1705 mysql: unspecified DoS vulnerability related to Server Optimizer (CPU Jan 2013)
CVE-2012-1705 mysql: unspecified DoS vulnerability related to Server Optimizer (CPU Jan 2013)
An unspecified vulnerability in the server optimizer subcomponent of the MySQL protocol component of the Oracle MySQL server allows remote authenticated attackers to alter availability via unspecified vectors.
References:
[1] http://www.oracle.com/technetwork/topics/security/cpujan2013-1515902.html
Discussion:
This issue affects the version of the mysql package, as shipped with Red Hat Enterprise Linux 6.
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 6
Via RHSA-2013:0219 https://rhn.redhat.com/errata/RHSA-2013-0219.html
Bugzilla
CVE-2012-0572 mysql: unspecified DoS vulnerability related to InnoDB (CPU Jan 2013)
bugzilla·2013-01-16·CVSS 4.0
CVE-2012-0572 [MEDIUM] CVE-2012-0572 mysql: unspecified DoS vulnerability related to InnoDB (CPU Jan 2013)
CVE-2012-0572 mysql: unspecified DoS vulnerability related to InnoDB (CPU Jan 2013)
An unspecified vulnerability in the InnoDB subcomponent of the MySQL protocol component of the Oracle MySQL server allows remote authenticated attackers to alter availability via unspecified vectors.
References:
[1] http://www.oracle.com/technetwork/topics/security/cpujan2013-1515902.html
Discussion:
This issue affects the version of the mysql package, as shipped with Red Hat Enterprise Linux 6.
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 6
Via RHSA-2013:0219 https://rhn.redhat.com/errata/RHSA-2013-0219.html
Bugzilla
CVE-2013-0219 sssd: TOCTOU race conditions by copying and removing directory trees
bugzilla·2012-12-05·CVSS 3.7
CVE-2013-0219 [LOW] CVE-2013-0219 sssd: TOCTOU race conditions by copying and removing directory trees
CVE-2013-0219 sssd: TOCTOU race conditions by copying and removing directory trees
A TOCTOU (time-of-check time-of-use) race condition was found in the way SSSD, System Security Services Daemon, performed copying and removal of (user) directory trees.A local attacker, with permissions to write into directory of the victim, being actively / currently copied / removed via the sssd daemon facility, could use this flaw to conduct symbolic link attacks, leading to their ability to alter / remove directories outside of originally intended, to be modified, directory tree.
This issue was found by Florian Weimer of Red Hat Product Security Team.
Discussion:
This issue affects the versions of the sssd package, as shipped with Red Hat Enterprise Linux 5 and 6.
--
This issue affects the versions
http://git.fedorahosted.org/cgit/sssd.git/commit/?id=020bf88fd1c5bdac8fc671b37c7118f5378c7047http://git.fedorahosted.org/cgit/sssd.git/commit/?id=3843b284cd3e8f88327772ebebc7249990fd87b9http://git.fedorahosted.org/cgit/sssd.git/commit/?id=94cbf1cfb0f88c967f1fb0a4cf23723148868e4ahttp://git.fedorahosted.org/cgit/sssd.git/commit/?id=e864d914a44a37016736554e9257c06b18c57d37http://lists.fedoraproject.org/pipermail/package-announce/2013-February/098434.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2013-February/098613.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0508.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1319.htmlhttp://secunia.com/advisories/51928http://secunia.com/advisories/52315http://www.securityfocus.com/bid/57539https://bugzilla.redhat.com/show_bug.cgi?id=884254https://fedorahosted.org/sssd/ticket/1782https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.4http://git.fedorahosted.org/cgit/sssd.git/commit/?id=020bf88fd1c5bdac8fc671b37c7118f5378c7047http://git.fedorahosted.org/cgit/sssd.git/commit/?id=3843b284cd3e8f88327772ebebc7249990fd87b9http://git.fedorahosted.org/cgit/sssd.git/commit/?id=94cbf1cfb0f88c967f1fb0a4cf23723148868e4ahttp://git.fedorahosted.org/cgit/sssd.git/commit/?id=e864d914a44a37016736554e9257c06b18c57d37http://lists.fedoraproject.org/pipermail/package-announce/2013-February/098434.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2013-February/098613.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0508.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1319.htmlhttp://secunia.com/advisories/51928http://secunia.com/advisories/52315http://www.securityfocus.com/bid/57539https://bugzilla.redhat.com/show_bug.cgi?id=884254https://fedorahosted.org/sssd/ticket/1782https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.4
2013-02-24
Published