Oval Definition:oval:com.ubuntu.trusty:def:201712173000
Revision Date:2018-07-27Version:1
Title:CVE-2017-12173 on Ubuntu 14.04 LTS (trusty) - medium.
Description:It was found that sssd's sysdb_search_user_by_upn_res() function before 1.16.0 did not sanitize requests when querying its local cache and was vulnerable to injection. In a centralized login environment, if a password hash was locally cached for a given user, an authenticated attacker could use this flaw to retrieve it.
Family:unixClass:vulnerability
Status:Reference(s):CVE-2017-12173
Platform(s):Ubuntu 14.04 LTS
Product(s):
Definition Synopsis
  • Ubuntu 14.04 LTS (trusty) is installed.
  • AND NOT While related to the CVE in some way, the 'sssd' package in trusty is not affected.
  • BACK