Bug 880245 - (CVE-2014-0249) VUL-1: CVE-2014-0249: sssd: incorrect expansion of group membership when encountering a non-POSIX group
(CVE-2014-0249)
VUL-1: CVE-2014-0249: sssd: incorrect expansion of group membership when enco...
Status: RESOLVED FIXED
Classification: Novell Products
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents
unspecified
Other Other
: P4 - Low : Minor
: ---
Assigned To: Security Team bot
Security Team bot
https://smash.suse.de/issue/99134/
CVSSv2:NVD:CVE-2014-0249:2.1:(AV:N/AC...
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2014-05-28 07:34 UTC by Sebastian Krahmer
Modified: 2019-04-24 15:48 UTC (History)
8 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Comment 1 SMASH SMASH 2014-05-28 07:40:11 UTC
Affected packages:

SLE-11-SP3: sssd
Comment 2 Sebastian Krahmer 2014-05-28 08:20:45 UTC
Putting to pending-list. Too minor issue to make SLE updates.
Comment 5 Howard Guo 2015-10-01 09:36:31 UTC
Set to private.
Comment 7 Howard Guo 2016-08-01 14:21:03 UTC
sorry, it was a mistake.
Comment 11 Swamp Workflow Management 2016-10-20 17:08:44 UTC
SUSE-SU-2016:2579-1: An update that solves one vulnerability and has three fixes is now available.

Category: security (moderate)
Bug References: 1002973,1004220,880245,993582
CVE References: CVE-2014-0249
Sources used:
SUSE Linux Enterprise Software Development Kit 12-SP1 (src):    sssd-1.11.5.1-28.1
SUSE Linux Enterprise Server 12-SP1 (src):    sssd-1.11.5.1-28.1
SUSE Linux Enterprise Desktop 12-SP1 (src):    sssd-1.11.5.1-28.1
Comment 12 Swamp Workflow Management 2016-10-26 16:24:37 UTC
openSUSE-SU-2016:2651-1: An update that solves one vulnerability and has three fixes is now available.

Category: security (moderate)
Bug References: 1002973,1004220,880245,993582
CVE References: CVE-2014-0249
Sources used:
openSUSE Leap 42.1 (src):    sssd-1.11.5.1-16.1
Comment 19 Samuel Cabrero 2019-04-22 11:07:53 UTC
Reassigned to the security team to evaluate closing it.