Back to search
CVE-2015-5292
Published: Oct 29, 2015
Modified: Aug 6, 2024
PUBLISHED
Description
Memory leak in the Privilege Attribute Certificate (PAC) responder plugin (sssd_pac_plugin.so) in System Security Services Daemon (SSSD) 1.10 before 1.13.1 allows remote authenticated users to cause a denial of service (memory consumption) via a large number of logins that trigger parsing of PAC blobs during Kerberos authentication.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
RHSA-2015:2355
vendor-advisory
x_refsource_REDHAT
RHSA-2015:2019
vendor-advisory
x_refsource_REDHAT
[sssd-users] 20151021 A security bug in SSSD 1.10 and later (CVE-2015-5292)
mailing-list
x_refsource_MLIST
1034038
vdb-entry
x_refsource_SECTRACK
77529
vdb-entry
x_refsource_BID
FEDORA-2015-cdea5324a8
vendor-advisory
x_refsource_FEDORA
FEDORA-2015-202c127199
vendor-advisory
x_refsource_FEDORA
https://bugzilla.redhat.com/show_bug.cgi?id=1267580
x_refsource_CONFIRM
FEDORA-2015-7b47df69d3
vendor-advisory
x_refsource_FEDORA
https://fedorahosted.org/sssd/ticket/2803
x_refsource_CONFIRM
https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.1
x_refsource_CONFIRM
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now