Red Hat Security Advisory 2015-2019-01

Discussion in 'News Aggregator' started by Packet Storm, 11 Nov 2015.

  1. Packet Storm

    Packet Storm Guest

    Red Hat Security Advisory 2015-2019-01 - The System Security Services Daemon service provides a set of daemons to manage access to remote directories and authentication mechanisms. It also provides the Name Service Switch and the Pluggable Authentication Modules interfaces toward the system, and a pluggable back-end system to connect to multiple different account sources. It was found that SSSD's Privilege Attribute Certificate responder plug-in would leak a small amount of memory on each authentication request. A remote attacker could potentially use this flaw to exhaust all available memory on the system by making repeated requests to a Kerberized daemon application configured to authenticate using the PAC responder plug-in.

    Continue reading...
     

Share This Page

Loading...