Oval Definition:oval:org.opensuse.security:def:95251
Revision Date:2022-06-15Version:1
Title:Security update for sssd (Moderate) (in QA)
Description:

This update for sssd fixes the following issues:

- CVE-2021-3621: Fixed shell command injection in sssctl via the logs-fetch and cache-expire subcommand (bsc#1189492).

- Add 'ldap_ignore_unreadable_references' parameter to skip unreadable objects referenced by 'member' attributte (bsc#1190775)

- Fix 32-bit libraries package. Libraries were moved from sssd to sssd-common but baselibs.conf was not updated accordingly (bsc#1182058, bsc#1196166)

- Remove caches only when performing a package downgrade. The sssd daemon takes care of upgrading the database format when necessary (bsc#1195552)

This patch is currently in QA and not yet available for download.
Family:unixClass:patch
Status:Reference(s):1182058
1182506
1189492
1190775
1195552
1196166
CVE-2021-31535
CVE-2021-3621
Platform(s):SUSE Linux Enterprise Desktop 15 SP4
SUSE Linux Enterprise High Performance Computing 15 SP4
SUSE Linux Enterprise Module for Basesystem 15 SP4
SUSE Linux Enterprise Module for Open Buildservice Development Tools 15 SP2
SUSE Linux Enterprise Server 15 SP4
SUSE Linux Enterprise Server for SAP Applications 15 SP4
SUSE Manager Proxy 4.3
SUSE Manager Retail Branch Server 4.3
SUSE Manager Server 4.3
Product(s):
Definition Synopsis
  • Release Information
  • SUSE Linux Enterprise Desktop 15 SP4 is installed
  • OR SUSE Linux Enterprise High Performance Computing 15 SP4 is installed
  • OR SUSE Linux Enterprise Module for Basesystem 15 SP4 is installed
  • OR SUSE Linux Enterprise Server 15 SP4 is installed
  • OR SUSE Linux Enterprise Server for SAP Applications 15 SP4 is installed
  • OR SUSE Manager Proxy 4.3 is installed
  • OR SUSE Manager Retail Branch Server 4.3 is installed
  • OR SUSE Manager Server 4.3 is installed
  • AND Package Information
  • libipa_hbac-devel-2.5.2-150400.4.5.14 is installed
  • OR libipa_hbac0-2.5.2-150400.4.5.14 is installed
  • OR libsss_certmap-devel-2.5.2-150400.4.5.14 is installed
  • OR libsss_certmap0-2.5.2-150400.4.5.14 is installed
  • OR libsss_idmap-devel-2.5.2-150400.4.5.14 is installed
  • OR libsss_idmap0-2.5.2-150400.4.5.14 is installed
  • OR libsss_nss_idmap-devel-2.5.2-150400.4.5.14 is installed
  • OR libsss_nss_idmap0-2.5.2-150400.4.5.14 is installed
  • OR libsss_simpleifp-devel-2.5.2-150400.4.5.14 is installed
  • OR libsss_simpleifp0-2.5.2-150400.4.5.14 is installed
  • OR python3-sssd-config-2.5.2-150400.4.5.14 is installed
  • OR sssd-2.5.2-150400.4.5.14 is installed
  • OR sssd-ad-2.5.2-150400.4.5.14 is installed
  • OR sssd-common-2.5.2-150400.4.5.14 is installed
  • OR sssd-dbus-2.5.2-150400.4.5.14 is installed
  • OR sssd-ipa-2.5.2-150400.4.5.14 is installed
  • OR sssd-kcm-2.5.2-150400.4.5.14 is installed
  • OR sssd-krb5-2.5.2-150400.4.5.14 is installed
  • OR sssd-krb5-common-2.5.2-150400.4.5.14 is installed
  • OR sssd-ldap-2.5.2-150400.4.5.14 is installed
  • OR sssd-proxy-2.5.2-150400.4.5.14 is installed
  • OR sssd-tools-2.5.2-150400.4.5.14 is installed
  • OR sssd-winbind-idmap-2.5.2-150400.4.5.14 is installed
  • BACK