CVE-2018-10852
published 2018-06-26CVE-2018-10852: The UNIX pipe which sudo uses to contact SSSD and read the available sudo rules from SSSD has too wide permissions, which means that anyone who can send a…
PriorityP339high7.5CVSS 3.0
AVNACLPRNUINSUCHINAN
EPSS
1.52%
71.9th percentile
The UNIX pipe which sudo uses to contact SSSD and read the available sudo rules from SSSD has too wide permissions, which means that anyone who can send a message using the same raw protocol that sudo and SSSD use can read the sudo rules available for any user. This affects versions of SSSD before 1.16.3.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | sssd | < sssd 1.16.3-1 (bookworm) | sssd 1.16.3-1 (bookworm) |
| fedoraproject | sssd | < 1.16.3 | 1.16.3 |
| fedoraproject | sssd | >= 0 < 1.16.3-1 | 1.16.3-1 |
| fedoraproject | sssd | >= 0 < 1.16.3-1 | 1.16.3-1 |
| fedoraproject | sssd | >= 0 < 1.16.3-1 | 1.16.3-1 |
| fedoraproject | sssd | >= 0 < 1.16.3-1 | 1.16.3-1 |
| fedoraproject | sssd | >= 0 < 1.16.1-1ubuntu1.8 | 1.16.1-1ubuntu1.8 |
| fedoraproject | sssd | >= 0 < 2.2.3-3ubuntu0.7 | 2.2.3-3ubuntu0.7 |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_workstation | — | — |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
osv7.5HIGH
vendor_debian3.8LOW
vendor_redhat3.8LOW
vendor_ubuntu3.8LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-fw39-25vp-7459: The UNIX pipe which sudo uses to contact SSSD and read the available sudo rules from SSSD has too wide permissions, which means that anyone who can se
ghsa_unreviewed·2022-05-13
CVE-2018-10852 [HIGH] CWE-200 GHSA-fw39-25vp-7459: The UNIX pipe which sudo uses to contact SSSD and read the available sudo rules from SSSD has too wide permissions, which means that anyone who can se
The UNIX pipe which sudo uses to contact SSSD and read the available sudo rules from SSSD has too wide permissions, which means that anyone who can send a message using the same raw protocol that sudo and SSSD use can read the sudo rules available for any user. This affects versions of SSSD before 1.16.3.
OSV
sssd vulnerabilities
osv·2021-09-08·CVSS 7.5
CVE-2018-10852 [HIGH] sssd vulnerabilities
sssd vulnerabilities
Jakub Hrozek discovered that SSSD incorrectly handled file permissions. A
local attacker could possibly use this issue to read the sudo rules
available for any user. This issue only affected Ubuntu 18.04 LTS.
(CVE-2018-10852)
It was discovered that SSSD incorrectly handled Group Policy Objects. When
SSSD is configured with too strict permissions causing the GPO to not be
readable, SSSD will allow all authenticated users to login instead of being
denied, contrary to expectations. This issue only affected Ubuntu 18.04
LTS. (CVE-2018-16838)
It was discovered that SSSD incorrectly handled users with no home
directory set. When no home directory was set, SSSD would return the root
directory instead of an empty string, possibly bypassing security measures.
This issue only
OSV
CVE-2018-10852: The UNIX pipe which sudo uses to contact SSSD and read the available sudo rules from SSSD has too wide permissions, which means that anyone who can se
osv·2018-06-26·CVSS 7.5
CVE-2018-10852 [HIGH] CVE-2018-10852: The UNIX pipe which sudo uses to contact SSSD and read the available sudo rules from SSSD has too wide permissions, which means that anyone who can se
The UNIX pipe which sudo uses to contact SSSD and read the available sudo rules from SSSD has too wide permissions, which means that anyone who can send a message using the same raw protocol that sudo and SSSD use can read the sudo rules available for any user. This affects versions of SSSD before 1.16.3.
Ubuntu
SSSD vulnerabilities
vendor_ubuntu·2021-09-08·CVSS 3.8
CVE-2021-3621 [LOW] SSSD vulnerabilities
Title: SSSD vulnerabilities
Summary: Several security issues were fixed in sssd.
Jakub Hrozek discovered that SSSD incorrectly handled file permissions. A
local attacker could possibly use this issue to read the sudo rules
available for any user. This issue only affected Ubuntu 18.04 LTS.
(CVE-2018-10852)
It was discovered that SSSD incorrectly handled Group Policy Objects. When
SSSD is configured with too strict permissions causing the GPO to not be
readable, SSSD will allow all authenticated users to login instead of being
denied, contrary to expectations. This issue only affected Ubuntu 18.04
LTS. (CVE-2018-16838)
It was discovered that SSSD incorrectly handled users with no home
directory set. When no home directory was set, SSSD would return the root
directory instead of an empty
Red Hat
sssd: information leak from the sssd-sudo responder
vendor_redhat·2018-06-26·CVSS 3.8
CVE-2018-10852 [LOW] CWE-200 sssd: information leak from the sssd-sudo responder
sssd: information leak from the sssd-sudo responder
The UNIX pipe which sudo uses to contact SSSD and read the available sudo rules from SSSD has too wide permissions, which means that anyone who can send a message using the same raw protocol that sudo and SSSD use can read the sudo rules available for any user. This affects versions of SSSD before 1.16.3.
The UNIX pipe which sudo uses to contact SSSD and read the available sudo rules from SSSD utilizes too broad of a set of permissions. Any user who can send a message using the same raw protocol that sudo and SSSD use can read the sudo rules available for any user.
Statement: Red Hat Satellite since version 6.4 uses sssd from the Red Hat Enterprise Linux repositories, where this vulnerability is fixed.
Package: sssd (Red Hat Enterpris
Debian
CVE-2018-10852: sssd - The UNIX pipe which sudo uses to contact SSSD and read the available sudo rules ...
vendor_debian·2018·CVSS 3.8
CVE-2018-10852 [LOW] CVE-2018-10852: sssd - The UNIX pipe which sudo uses to contact SSSD and read the available sudo rules ...
The UNIX pipe which sudo uses to contact SSSD and read the available sudo rules from SSSD has too wide permissions, which means that anyone who can send a message using the same raw protocol that sudo and SSSD use can read the sudo rules available for any user. This affects versions of SSSD before 1.16.3.
Scope: local
bookworm: resolved (fixed in 1.16.3-1)
bullseye: resolved (fixed in 1.16.3-1)
forky: resolved (fixed in 1.16.3-1)
sid: resolved (fixed in 1.16.3-1)
trixie: resolved (fixed in 1.16.3-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-10852 sssd: information leak from the sssd-sudo responder [fedora-all]
bugzilla·2018-06-26·CVSS 3.8
CVE-2018-10852 [LOW] CVE-2018-10852 sssd: information leak from the sssd-sudo responder [fedora-all]
CVE-2018-10852 sssd: information leak from the sssd-sudo responder [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versio
Bugzilla
CVE-2018-10852 sssd: information leak from the sssd-sudo responder
bugzilla·2018-06-07·CVSS 3.8
CVE-2018-10852 [LOW] CVE-2018-10852 sssd: information leak from the sssd-sudo responder
CVE-2018-10852 sssd: information leak from the sssd-sudo responder
The UNIX pipe which sudo uses to contact SSSD and read the available sudo rules from SSSD has too wide permissions, which means that anyone who can send a message using the same raw protocol that sudo and SSSD use can read the sudo rules available for any user.
Discussion:
Acknowledgments:
Name: Jakub Hrozek (Red Hat)
---
External References:
https://pagure.io/SSSD/sssd/issue/3766
---
Created sssd tracking bugs for this issue:
Affects: fedora-all [bug 1595056]
---
To test, it is sufficient to "ls -l /var/lib/sss/pipes/sudo". Before the patch, the permissions were open to anyone, after the patch, only root should have either read or write permissions.
---
This issue has been addressed in the following products:
http://www.securityfocus.com/bid/104547https://access.redhat.com/errata/RHSA-2018:3158https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-10852https://lists.debian.org/debian-lts-announce/2018/07/msg00019.htmlhttp://www.securityfocus.com/bid/104547https://access.redhat.com/errata/RHSA-2018:3158https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-10852https://lists.debian.org/debian-lts-announce/2018/07/msg00019.html
2018-06-26
Published