-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

===========================================================================
             AUSCERT External Security Bulletin Redistribution

                               ESB-2018.3407
            Low: sssd security, bug fix, and enhancement update
                              31 October 2018

===========================================================================

        AusCERT Security Bulletin Summary
        ---------------------------------

Product:           sssd
Publisher:         Red Hat
Operating System:  Red Hat Enterprise Linux Server 7
                   Red Hat Enterprise Linux WS/Desktop 7
Impact/Access:     Access Confidential Data -- Existing Account
Resolution:        Patch/Upgrade
CVE Names:         CVE-2018-10852  

Reference:         ESB-2018.2065

Original Bulletin: 
   https://access.redhat.com/errata/RHSA-2018:3158

- --------------------------BEGIN INCLUDED TEXT--------------------

- -----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

=====================================================================
                   Red Hat Security Advisory

Synopsis:          Low: sssd security, bug fix, and enhancement update
Advisory ID:       RHSA-2018:3158-01
Product:           Red Hat Enterprise Linux
Advisory URL:      https://access.redhat.com/errata/RHSA-2018:3158
Issue date:        2018-10-30
CVE Names:         CVE-2018-10852 
=====================================================================

1. Summary:

An update for sssd is now available for Red Hat Enterprise Linux 7.

Red Hat Product Security has rated this update as having a security impact
of Low. A Common Vulnerability Scoring System (CVSS) base score, which
gives a detailed severity rating, is available for each vulnerability from
the CVE link(s) in the References section.

2. Relevant releases/architectures:

Red Hat Enterprise Linux Client (v. 7) - noarch, x86_64
Red Hat Enterprise Linux Client Optional (v. 7) - x86_64
Red Hat Enterprise Linux ComputeNode (v. 7) - noarch, x86_64
Red Hat Enterprise Linux ComputeNode Optional (v. 7) - x86_64
Red Hat Enterprise Linux Server (v. 7) - noarch, ppc64, ppc64le, s390x, x86_64
Red Hat Enterprise Linux Server Optional (v. 7) - ppc64, ppc64le, s390x, x86_64
Red Hat Enterprise Linux Workstation (v. 7) - noarch, x86_64
Red Hat Enterprise Linux Workstation Optional (v. 7) - x86_64
Red Hat Enterprise Linux for ARM and IBM Power LE (POWER9) Server (v. 7) - aarch64, noarch, ppc64le, s390x
Red Hat Enterprise Linux for ARM and IBM Power LE (POWER9) Server Optional (v. 7) - aarch64, ppc64le, s390x

3. Description:

The System Security Services Daemon (SSSD) service provides a set of
daemons to manage access to remote directories and authentication
mechanisms. It also provides the Name Service Switch (NSS) and the
Pluggable Authentication Modules (PAM) interfaces toward the system, and a
pluggable back-end system to connect to multiple different account sources.

The following packages have been upgraded to a later upstream version: sssd
(1.16.2). (BZ#1558498)

Security Fix(es):

* sssd: information leak from the sssd-sudo responder (CVE-2018-10852)

For more details about the security issue(s), including the impact, a CVSS
score, and other related information, refer to the CVE page(s) listed in
the References section.

This issue was discovered by Jakub Hrozek (Red Hat).

Additional Changes:

For detailed information on changes in this release, see the Red Hat
Enterprise Linux 7.6 Release Notes linked from the References section.

4. Solution:

For details on how to apply this update, which includes the changes
described in this advisory, refer to:

https://access.redhat.com/articles/11258

5. Bugs fixed (https://bugzilla.redhat.com/):

1385665 - Incorrect error code returned from krb5_child (updated)
1416528 - sssd in cross realm trust configuration should be able to use AD KDCs from a client site defined in sssd.conf or a snippet
1459348 - extend sss-certmap man page regarding priority processing
1509691 - Document how to change the regular expression for SSSD so that group names with an @-sign can be parsed
1514061 - ID override GID from Default Trust View is not properly resolved in case domain resolution order is set
1516266 - Give a more detailed debug and system-log message if krb5_init_context() failed
1522928 - sssd doesn't allow user with expired password to login when PasswordgraceLimit set
1534749 - Requesting an AD user's private group and then the user itself returns an emty homedir
1537272 - SSH public key authentication keeps working after keys are removed from ID view
1537279 - Certificate is not removed from cache when it's removed from the override
1538555 - crash in nss_protocol_fill_netgrent. sssd_nss[19234]: segfault at 80 ip 000055612688c2a0 sp 00007ffddf9b9cd0 error 4 in sssd_nss[55612687e000+39000]
1546754 - The man page of sss_ssh_authorizedkeys can be enhanced to better explain how the keys are retrieved and how X.509 certificates can be used
1558498 - Rebase sssd to the latests upstream release of the 1.16 branch
1562025 - externalUser sudo attribute must be fully-qualified
1565774 - After updating to RHEL 7.5 failing to clear the sssd cache
1566782 - memory management issue in the sssd_nss_ex interface can cause the ns-slapd process on IPA server to crash
1571526 - SSSD with ID provider 'ad' should give a warning in case the ldap schema is manually changed to something different than 'ad'.
1577335 - /usr/libexec/sssd/sssd_autofs SIGABRT crash daily
1578291 - Samba can not register sss idmap module because it's using an outdated SMB_IDMAP_INTERFACE_VERSION
1583251 - home dir disappear in sssd cache on the IPA master for AD users
1583725 - SSSD AD uses LDAP filter to detect POSIX attributes stored in AD GC also for regular AD DC queries
1588810 - CVE-2018-10852 sssd: information leak from the sssd-sudo responder
1600822 - SSSD bails out saving desktop profiles in case an invalid profile is found
1602781 - Offline logins and/or id_provider=local logins fail after upgrade to 7.6
1607313 - When sssd is running as non-root user, the sudo pipe is created as sssd:sssd but then the private pipe ownership fails
1610667 - sssd_ssh leaks file descriptors when more than one certificate is converted into an SSH key

6. Package List:

Red Hat Enterprise Linux Client (v. 7):

Source:
sssd-1.16.2-13.el7.src.rpm

noarch:
python-sssdconfig-1.16.2-13.el7.noarch.rpm

x86_64:
libipa_hbac-1.16.2-13.el7.i686.rpm
libipa_hbac-1.16.2-13.el7.x86_64.rpm
libsss_autofs-1.16.2-13.el7.x86_64.rpm
libsss_certmap-1.16.2-13.el7.i686.rpm
libsss_certmap-1.16.2-13.el7.x86_64.rpm
libsss_idmap-1.16.2-13.el7.i686.rpm
libsss_idmap-1.16.2-13.el7.x86_64.rpm
libsss_nss_idmap-1.16.2-13.el7.i686.rpm
libsss_nss_idmap-1.16.2-13.el7.x86_64.rpm
libsss_simpleifp-1.16.2-13.el7.i686.rpm
libsss_simpleifp-1.16.2-13.el7.x86_64.rpm
libsss_sudo-1.16.2-13.el7.x86_64.rpm
python-libipa_hbac-1.16.2-13.el7.x86_64.rpm
python-sss-1.16.2-13.el7.x86_64.rpm
python-sss-murmur-1.16.2-13.el7.x86_64.rpm
sssd-1.16.2-13.el7.x86_64.rpm
sssd-ad-1.16.2-13.el7.x86_64.rpm
sssd-client-1.16.2-13.el7.i686.rpm
sssd-client-1.16.2-13.el7.x86_64.rpm
sssd-common-1.16.2-13.el7.x86_64.rpm
sssd-common-pac-1.16.2-13.el7.x86_64.rpm
sssd-dbus-1.16.2-13.el7.x86_64.rpm
sssd-debuginfo-1.16.2-13.el7.i686.rpm
sssd-debuginfo-1.16.2-13.el7.x86_64.rpm
sssd-ipa-1.16.2-13.el7.x86_64.rpm
sssd-kcm-1.16.2-13.el7.x86_64.rpm
sssd-krb5-1.16.2-13.el7.x86_64.rpm
sssd-krb5-common-1.16.2-13.el7.x86_64.rpm
sssd-ldap-1.16.2-13.el7.x86_64.rpm
sssd-libwbclient-1.16.2-13.el7.x86_64.rpm
sssd-polkit-rules-1.16.2-13.el7.x86_64.rpm
sssd-proxy-1.16.2-13.el7.x86_64.rpm
sssd-tools-1.16.2-13.el7.x86_64.rpm
sssd-winbind-idmap-1.16.2-13.el7.x86_64.rpm

Red Hat Enterprise Linux Client Optional (v. 7):

x86_64:
libipa_hbac-devel-1.16.2-13.el7.i686.rpm
libipa_hbac-devel-1.16.2-13.el7.x86_64.rpm
libsss_certmap-devel-1.16.2-13.el7.i686.rpm
libsss_certmap-devel-1.16.2-13.el7.x86_64.rpm
libsss_idmap-devel-1.16.2-13.el7.i686.rpm
libsss_idmap-devel-1.16.2-13.el7.x86_64.rpm
libsss_nss_idmap-devel-1.16.2-13.el7.i686.rpm
libsss_nss_idmap-devel-1.16.2-13.el7.x86_64.rpm
libsss_simpleifp-devel-1.16.2-13.el7.i686.rpm
libsss_simpleifp-devel-1.16.2-13.el7.x86_64.rpm
python-libsss_nss_idmap-1.16.2-13.el7.x86_64.rpm
sssd-debuginfo-1.16.2-13.el7.i686.rpm
sssd-debuginfo-1.16.2-13.el7.x86_64.rpm
sssd-libwbclient-devel-1.16.2-13.el7.i686.rpm
sssd-libwbclient-devel-1.16.2-13.el7.x86_64.rpm

Red Hat Enterprise Linux ComputeNode (v. 7):

Source:
sssd-1.16.2-13.el7.src.rpm

noarch:
python-sssdconfig-1.16.2-13.el7.noarch.rpm

x86_64:
libipa_hbac-1.16.2-13.el7.i686.rpm
libipa_hbac-1.16.2-13.el7.x86_64.rpm
libsss_autofs-1.16.2-13.el7.x86_64.rpm
libsss_certmap-1.16.2-13.el7.i686.rpm
libsss_certmap-1.16.2-13.el7.x86_64.rpm
libsss_idmap-1.16.2-13.el7.i686.rpm
libsss_idmap-1.16.2-13.el7.x86_64.rpm
libsss_nss_idmap-1.16.2-13.el7.i686.rpm
libsss_nss_idmap-1.16.2-13.el7.x86_64.rpm
libsss_simpleifp-1.16.2-13.el7.i686.rpm
libsss_simpleifp-1.16.2-13.el7.x86_64.rpm
libsss_sudo-1.16.2-13.el7.x86_64.rpm
python-libipa_hbac-1.16.2-13.el7.x86_64.rpm
python-sss-1.16.2-13.el7.x86_64.rpm
python-sss-murmur-1.16.2-13.el7.x86_64.rpm
sssd-1.16.2-13.el7.x86_64.rpm
sssd-ad-1.16.2-13.el7.x86_64.rpm
sssd-client-1.16.2-13.el7.i686.rpm
sssd-client-1.16.2-13.el7.x86_64.rpm
sssd-common-1.16.2-13.el7.x86_64.rpm
sssd-common-pac-1.16.2-13.el7.x86_64.rpm
sssd-dbus-1.16.2-13.el7.x86_64.rpm
sssd-debuginfo-1.16.2-13.el7.i686.rpm
sssd-debuginfo-1.16.2-13.el7.x86_64.rpm
sssd-ipa-1.16.2-13.el7.x86_64.rpm
sssd-kcm-1.16.2-13.el7.x86_64.rpm
sssd-krb5-1.16.2-13.el7.x86_64.rpm
sssd-krb5-common-1.16.2-13.el7.x86_64.rpm
sssd-ldap-1.16.2-13.el7.x86_64.rpm
sssd-libwbclient-1.16.2-13.el7.x86_64.rpm
sssd-polkit-rules-1.16.2-13.el7.x86_64.rpm
sssd-proxy-1.16.2-13.el7.x86_64.rpm
sssd-tools-1.16.2-13.el7.x86_64.rpm
sssd-winbind-idmap-1.16.2-13.el7.x86_64.rpm

Red Hat Enterprise Linux ComputeNode Optional (v. 7):

x86_64:
libipa_hbac-devel-1.16.2-13.el7.i686.rpm
libipa_hbac-devel-1.16.2-13.el7.x86_64.rpm
libsss_certmap-devel-1.16.2-13.el7.i686.rpm
libsss_certmap-devel-1.16.2-13.el7.x86_64.rpm
libsss_idmap-devel-1.16.2-13.el7.i686.rpm
libsss_idmap-devel-1.16.2-13.el7.x86_64.rpm
libsss_nss_idmap-devel-1.16.2-13.el7.i686.rpm
libsss_nss_idmap-devel-1.16.2-13.el7.x86_64.rpm
libsss_simpleifp-devel-1.16.2-13.el7.i686.rpm
libsss_simpleifp-devel-1.16.2-13.el7.x86_64.rpm
python-libsss_nss_idmap-1.16.2-13.el7.x86_64.rpm
sssd-debuginfo-1.16.2-13.el7.i686.rpm
sssd-debuginfo-1.16.2-13.el7.x86_64.rpm
sssd-libwbclient-devel-1.16.2-13.el7.i686.rpm
sssd-libwbclient-devel-1.16.2-13.el7.x86_64.rpm

Red Hat Enterprise Linux Server (v. 7):

Source:
sssd-1.16.2-13.el7.src.rpm

noarch:
python-sssdconfig-1.16.2-13.el7.noarch.rpm

ppc64:
libipa_hbac-1.16.2-13.el7.ppc.rpm
libipa_hbac-1.16.2-13.el7.ppc64.rpm
libsss_autofs-1.16.2-13.el7.ppc64.rpm
libsss_certmap-1.16.2-13.el7.ppc.rpm
libsss_certmap-1.16.2-13.el7.ppc64.rpm
libsss_idmap-1.16.2-13.el7.ppc.rpm
libsss_idmap-1.16.2-13.el7.ppc64.rpm
libsss_nss_idmap-1.16.2-13.el7.ppc.rpm
libsss_nss_idmap-1.16.2-13.el7.ppc64.rpm
libsss_simpleifp-1.16.2-13.el7.ppc.rpm
libsss_simpleifp-1.16.2-13.el7.ppc64.rpm
libsss_sudo-1.16.2-13.el7.ppc64.rpm
python-libipa_hbac-1.16.2-13.el7.ppc64.rpm
python-sss-1.16.2-13.el7.ppc64.rpm
python-sss-murmur-1.16.2-13.el7.ppc64.rpm
sssd-1.16.2-13.el7.ppc64.rpm
sssd-ad-1.16.2-13.el7.ppc64.rpm
sssd-client-1.16.2-13.el7.ppc.rpm
sssd-client-1.16.2-13.el7.ppc64.rpm
sssd-common-1.16.2-13.el7.ppc64.rpm
sssd-common-pac-1.16.2-13.el7.ppc64.rpm
sssd-dbus-1.16.2-13.el7.ppc64.rpm
sssd-debuginfo-1.16.2-13.el7.ppc.rpm
sssd-debuginfo-1.16.2-13.el7.ppc64.rpm
sssd-ipa-1.16.2-13.el7.ppc64.rpm
sssd-kcm-1.16.2-13.el7.ppc64.rpm
sssd-krb5-1.16.2-13.el7.ppc64.rpm
sssd-krb5-common-1.16.2-13.el7.ppc64.rpm
sssd-ldap-1.16.2-13.el7.ppc64.rpm
sssd-libwbclient-1.16.2-13.el7.ppc64.rpm
sssd-polkit-rules-1.16.2-13.el7.ppc64.rpm
sssd-proxy-1.16.2-13.el7.ppc64.rpm
sssd-tools-1.16.2-13.el7.ppc64.rpm
sssd-winbind-idmap-1.16.2-13.el7.ppc64.rpm

ppc64le:
libipa_hbac-1.16.2-13.el7.ppc64le.rpm
libsss_autofs-1.16.2-13.el7.ppc64le.rpm
libsss_certmap-1.16.2-13.el7.ppc64le.rpm
libsss_idmap-1.16.2-13.el7.ppc64le.rpm
libsss_nss_idmap-1.16.2-13.el7.ppc64le.rpm
libsss_simpleifp-1.16.2-13.el7.ppc64le.rpm
libsss_sudo-1.16.2-13.el7.ppc64le.rpm
python-libipa_hbac-1.16.2-13.el7.ppc64le.rpm
python-sss-1.16.2-13.el7.ppc64le.rpm
python-sss-murmur-1.16.2-13.el7.ppc64le.rpm
sssd-1.16.2-13.el7.ppc64le.rpm
sssd-ad-1.16.2-13.el7.ppc64le.rpm
sssd-client-1.16.2-13.el7.ppc64le.rpm
sssd-common-1.16.2-13.el7.ppc64le.rpm
sssd-common-pac-1.16.2-13.el7.ppc64le.rpm
sssd-dbus-1.16.2-13.el7.ppc64le.rpm
sssd-debuginfo-1.16.2-13.el7.ppc64le.rpm
sssd-ipa-1.16.2-13.el7.ppc64le.rpm
sssd-kcm-1.16.2-13.el7.ppc64le.rpm
sssd-krb5-1.16.2-13.el7.ppc64le.rpm
sssd-krb5-common-1.16.2-13.el7.ppc64le.rpm
sssd-ldap-1.16.2-13.el7.ppc64le.rpm
sssd-libwbclient-1.16.2-13.el7.ppc64le.rpm
sssd-polkit-rules-1.16.2-13.el7.ppc64le.rpm
sssd-proxy-1.16.2-13.el7.ppc64le.rpm
sssd-tools-1.16.2-13.el7.ppc64le.rpm
sssd-winbind-idmap-1.16.2-13.el7.ppc64le.rpm

s390x:
libipa_hbac-1.16.2-13.el7.s390.rpm
libipa_hbac-1.16.2-13.el7.s390x.rpm
libsss_autofs-1.16.2-13.el7.s390x.rpm
libsss_certmap-1.16.2-13.el7.s390.rpm
libsss_certmap-1.16.2-13.el7.s390x.rpm
libsss_idmap-1.16.2-13.el7.s390.rpm
libsss_idmap-1.16.2-13.el7.s390x.rpm
libsss_nss_idmap-1.16.2-13.el7.s390.rpm
libsss_nss_idmap-1.16.2-13.el7.s390x.rpm
libsss_simpleifp-1.16.2-13.el7.s390.rpm
libsss_simpleifp-1.16.2-13.el7.s390x.rpm
libsss_sudo-1.16.2-13.el7.s390x.rpm
python-libipa_hbac-1.16.2-13.el7.s390x.rpm
python-sss-1.16.2-13.el7.s390x.rpm
python-sss-murmur-1.16.2-13.el7.s390x.rpm
sssd-1.16.2-13.el7.s390x.rpm
sssd-ad-1.16.2-13.el7.s390x.rpm
sssd-client-1.16.2-13.el7.s390.rpm
sssd-client-1.16.2-13.el7.s390x.rpm
sssd-common-1.16.2-13.el7.s390x.rpm
sssd-common-pac-1.16.2-13.el7.s390x.rpm
sssd-dbus-1.16.2-13.el7.s390x.rpm
sssd-debuginfo-1.16.2-13.el7.s390.rpm
sssd-debuginfo-1.16.2-13.el7.s390x.rpm
sssd-ipa-1.16.2-13.el7.s390x.rpm
sssd-kcm-1.16.2-13.el7.s390x.rpm
sssd-krb5-1.16.2-13.el7.s390x.rpm
sssd-krb5-common-1.16.2-13.el7.s390x.rpm
sssd-ldap-1.16.2-13.el7.s390x.rpm
sssd-libwbclient-1.16.2-13.el7.s390x.rpm
sssd-polkit-rules-1.16.2-13.el7.s390x.rpm
sssd-proxy-1.16.2-13.el7.s390x.rpm
sssd-tools-1.16.2-13.el7.s390x.rpm
sssd-winbind-idmap-1.16.2-13.el7.s390x.rpm

x86_64:
libipa_hbac-1.16.2-13.el7.i686.rpm
libipa_hbac-1.16.2-13.el7.x86_64.rpm
libsss_autofs-1.16.2-13.el7.x86_64.rpm
libsss_certmap-1.16.2-13.el7.i686.rpm
libsss_certmap-1.16.2-13.el7.x86_64.rpm
libsss_idmap-1.16.2-13.el7.i686.rpm
libsss_idmap-1.16.2-13.el7.x86_64.rpm
libsss_nss_idmap-1.16.2-13.el7.i686.rpm
libsss_nss_idmap-1.16.2-13.el7.x86_64.rpm
libsss_simpleifp-1.16.2-13.el7.i686.rpm
libsss_simpleifp-1.16.2-13.el7.x86_64.rpm
libsss_sudo-1.16.2-13.el7.x86_64.rpm
python-libipa_hbac-1.16.2-13.el7.x86_64.rpm
python-libsss_nss_idmap-1.16.2-13.el7.x86_64.rpm
python-sss-1.16.2-13.el7.x86_64.rpm
python-sss-murmur-1.16.2-13.el7.x86_64.rpm
sssd-1.16.2-13.el7.x86_64.rpm
sssd-ad-1.16.2-13.el7.x86_64.rpm
sssd-client-1.16.2-13.el7.i686.rpm
sssd-client-1.16.2-13.el7.x86_64.rpm
sssd-common-1.16.2-13.el7.x86_64.rpm
sssd-common-pac-1.16.2-13.el7.x86_64.rpm
sssd-dbus-1.16.2-13.el7.x86_64.rpm
sssd-debuginfo-1.16.2-13.el7.i686.rpm
sssd-debuginfo-1.16.2-13.el7.x86_64.rpm
sssd-ipa-1.16.2-13.el7.x86_64.rpm
sssd-kcm-1.16.2-13.el7.x86_64.rpm
sssd-krb5-1.16.2-13.el7.x86_64.rpm
sssd-krb5-common-1.16.2-13.el7.x86_64.rpm
sssd-ldap-1.16.2-13.el7.x86_64.rpm
sssd-libwbclient-1.16.2-13.el7.x86_64.rpm
sssd-polkit-rules-1.16.2-13.el7.x86_64.rpm
sssd-proxy-1.16.2-13.el7.x86_64.rpm
sssd-tools-1.16.2-13.el7.x86_64.rpm
sssd-winbind-idmap-1.16.2-13.el7.x86_64.rpm

Red Hat Enterprise Linux for ARM and IBM Power LE (POWER9) Server (v. 7):

Source:
sssd-1.16.2-13.el7.src.rpm

aarch64:
libipa_hbac-1.16.2-13.el7.aarch64.rpm
libsss_autofs-1.16.2-13.el7.aarch64.rpm
libsss_certmap-1.16.2-13.el7.aarch64.rpm
libsss_idmap-1.16.2-13.el7.aarch64.rpm
libsss_nss_idmap-1.16.2-13.el7.aarch64.rpm
libsss_simpleifp-1.16.2-13.el7.aarch64.rpm
libsss_sudo-1.16.2-13.el7.aarch64.rpm
python-libipa_hbac-1.16.2-13.el7.aarch64.rpm
python-libsss_nss_idmap-1.16.2-13.el7.aarch64.rpm
python-sss-1.16.2-13.el7.aarch64.rpm
python-sss-murmur-1.16.2-13.el7.aarch64.rpm
sssd-1.16.2-13.el7.aarch64.rpm
sssd-ad-1.16.2-13.el7.aarch64.rpm
sssd-client-1.16.2-13.el7.aarch64.rpm
sssd-common-1.16.2-13.el7.aarch64.rpm
sssd-common-pac-1.16.2-13.el7.aarch64.rpm
sssd-dbus-1.16.2-13.el7.aarch64.rpm
sssd-debuginfo-1.16.2-13.el7.aarch64.rpm
sssd-ipa-1.16.2-13.el7.aarch64.rpm
sssd-kcm-1.16.2-13.el7.aarch64.rpm
sssd-krb5-1.16.2-13.el7.aarch64.rpm
sssd-krb5-common-1.16.2-13.el7.aarch64.rpm
sssd-ldap-1.16.2-13.el7.aarch64.rpm
sssd-libwbclient-1.16.2-13.el7.aarch64.rpm
sssd-polkit-rules-1.16.2-13.el7.aarch64.rpm
sssd-proxy-1.16.2-13.el7.aarch64.rpm
sssd-tools-1.16.2-13.el7.aarch64.rpm
sssd-winbind-idmap-1.16.2-13.el7.aarch64.rpm

noarch:
python-sssdconfig-1.16.2-13.el7.noarch.rpm

ppc64le:
libipa_hbac-1.16.2-13.el7.ppc64le.rpm
libsss_autofs-1.16.2-13.el7.ppc64le.rpm
libsss_certmap-1.16.2-13.el7.ppc64le.rpm
libsss_idmap-1.16.2-13.el7.ppc64le.rpm
libsss_nss_idmap-1.16.2-13.el7.ppc64le.rpm
libsss_simpleifp-1.16.2-13.el7.ppc64le.rpm
libsss_sudo-1.16.2-13.el7.ppc64le.rpm
python-libipa_hbac-1.16.2-13.el7.ppc64le.rpm
python-sss-1.16.2-13.el7.ppc64le.rpm
python-sss-murmur-1.16.2-13.el7.ppc64le.rpm
sssd-1.16.2-13.el7.ppc64le.rpm
sssd-ad-1.16.2-13.el7.ppc64le.rpm
sssd-client-1.16.2-13.el7.ppc64le.rpm
sssd-common-1.16.2-13.el7.ppc64le.rpm
sssd-common-pac-1.16.2-13.el7.ppc64le.rpm
sssd-dbus-1.16.2-13.el7.ppc64le.rpm
sssd-debuginfo-1.16.2-13.el7.ppc64le.rpm
sssd-ipa-1.16.2-13.el7.ppc64le.rpm
sssd-kcm-1.16.2-13.el7.ppc64le.rpm
sssd-krb5-1.16.2-13.el7.ppc64le.rpm
sssd-krb5-common-1.16.2-13.el7.ppc64le.rpm
sssd-ldap-1.16.2-13.el7.ppc64le.rpm
sssd-libwbclient-1.16.2-13.el7.ppc64le.rpm
sssd-polkit-rules-1.16.2-13.el7.ppc64le.rpm
sssd-proxy-1.16.2-13.el7.ppc64le.rpm
sssd-tools-1.16.2-13.el7.ppc64le.rpm
sssd-winbind-idmap-1.16.2-13.el7.ppc64le.rpm

s390x:
libipa_hbac-1.16.2-13.el7.s390.rpm
libipa_hbac-1.16.2-13.el7.s390x.rpm
libsss_autofs-1.16.2-13.el7.s390x.rpm
libsss_certmap-1.16.2-13.el7.s390.rpm
libsss_certmap-1.16.2-13.el7.s390x.rpm
libsss_idmap-1.16.2-13.el7.s390.rpm
libsss_idmap-1.16.2-13.el7.s390x.rpm
libsss_nss_idmap-1.16.2-13.el7.s390.rpm
libsss_nss_idmap-1.16.2-13.el7.s390x.rpm
libsss_simpleifp-1.16.2-13.el7.s390.rpm
libsss_simpleifp-1.16.2-13.el7.s390x.rpm
libsss_sudo-1.16.2-13.el7.s390x.rpm
python-libipa_hbac-1.16.2-13.el7.s390x.rpm
python-sss-1.16.2-13.el7.s390x.rpm
python-sss-murmur-1.16.2-13.el7.s390x.rpm
sssd-1.16.2-13.el7.s390x.rpm
sssd-ad-1.16.2-13.el7.s390x.rpm
sssd-client-1.16.2-13.el7.s390.rpm
sssd-client-1.16.2-13.el7.s390x.rpm
sssd-common-1.16.2-13.el7.s390x.rpm
sssd-common-pac-1.16.2-13.el7.s390x.rpm
sssd-dbus-1.16.2-13.el7.s390x.rpm
sssd-debuginfo-1.16.2-13.el7.s390.rpm
sssd-debuginfo-1.16.2-13.el7.s390x.rpm
sssd-ipa-1.16.2-13.el7.s390x.rpm
sssd-kcm-1.16.2-13.el7.s390x.rpm
sssd-krb5-1.16.2-13.el7.s390x.rpm
sssd-krb5-common-1.16.2-13.el7.s390x.rpm
sssd-ldap-1.16.2-13.el7.s390x.rpm
sssd-libwbclient-1.16.2-13.el7.s390x.rpm
sssd-polkit-rules-1.16.2-13.el7.s390x.rpm
sssd-proxy-1.16.2-13.el7.s390x.rpm
sssd-tools-1.16.2-13.el7.s390x.rpm
sssd-winbind-idmap-1.16.2-13.el7.s390x.rpm

Red Hat Enterprise Linux for ARM and IBM Power LE (POWER9) Server Optional (v. 7):

aarch64:
libipa_hbac-devel-1.16.2-13.el7.aarch64.rpm
libsss_certmap-devel-1.16.2-13.el7.aarch64.rpm
libsss_idmap-devel-1.16.2-13.el7.aarch64.rpm
libsss_nss_idmap-devel-1.16.2-13.el7.aarch64.rpm
libsss_simpleifp-devel-1.16.2-13.el7.aarch64.rpm
sssd-debuginfo-1.16.2-13.el7.aarch64.rpm
sssd-libwbclient-devel-1.16.2-13.el7.aarch64.rpm

ppc64le:
libipa_hbac-devel-1.16.2-13.el7.ppc64le.rpm
libsss_certmap-devel-1.16.2-13.el7.ppc64le.rpm
libsss_idmap-devel-1.16.2-13.el7.ppc64le.rpm
libsss_nss_idmap-devel-1.16.2-13.el7.ppc64le.rpm
libsss_simpleifp-devel-1.16.2-13.el7.ppc64le.rpm
python-libsss_nss_idmap-1.16.2-13.el7.ppc64le.rpm
sssd-debuginfo-1.16.2-13.el7.ppc64le.rpm
sssd-libwbclient-devel-1.16.2-13.el7.ppc64le.rpm

s390x:
libipa_hbac-devel-1.16.2-13.el7.s390.rpm
libipa_hbac-devel-1.16.2-13.el7.s390x.rpm
libsss_certmap-devel-1.16.2-13.el7.s390.rpm
libsss_certmap-devel-1.16.2-13.el7.s390x.rpm
libsss_idmap-devel-1.16.2-13.el7.s390.rpm
libsss_idmap-devel-1.16.2-13.el7.s390x.rpm
libsss_nss_idmap-devel-1.16.2-13.el7.s390.rpm
libsss_nss_idmap-devel-1.16.2-13.el7.s390x.rpm
libsss_simpleifp-devel-1.16.2-13.el7.s390.rpm
libsss_simpleifp-devel-1.16.2-13.el7.s390x.rpm
python-libsss_nss_idmap-1.16.2-13.el7.s390x.rpm
sssd-debuginfo-1.16.2-13.el7.s390.rpm
sssd-debuginfo-1.16.2-13.el7.s390x.rpm
sssd-libwbclient-devel-1.16.2-13.el7.s390.rpm
sssd-libwbclient-devel-1.16.2-13.el7.s390x.rpm

Red Hat Enterprise Linux Server Optional (v. 7):

ppc64:
libipa_hbac-devel-1.16.2-13.el7.ppc.rpm
libipa_hbac-devel-1.16.2-13.el7.ppc64.rpm
libsss_certmap-devel-1.16.2-13.el7.ppc.rpm
libsss_certmap-devel-1.16.2-13.el7.ppc64.rpm
libsss_idmap-devel-1.16.2-13.el7.ppc.rpm
libsss_idmap-devel-1.16.2-13.el7.ppc64.rpm
libsss_nss_idmap-devel-1.16.2-13.el7.ppc.rpm
libsss_nss_idmap-devel-1.16.2-13.el7.ppc64.rpm
libsss_simpleifp-devel-1.16.2-13.el7.ppc.rpm
libsss_simpleifp-devel-1.16.2-13.el7.ppc64.rpm
python-libsss_nss_idmap-1.16.2-13.el7.ppc64.rpm
sssd-debuginfo-1.16.2-13.el7.ppc.rpm
sssd-debuginfo-1.16.2-13.el7.ppc64.rpm
sssd-libwbclient-devel-1.16.2-13.el7.ppc.rpm
sssd-libwbclient-devel-1.16.2-13.el7.ppc64.rpm

ppc64le:
libipa_hbac-devel-1.16.2-13.el7.ppc64le.rpm
libsss_certmap-devel-1.16.2-13.el7.ppc64le.rpm
libsss_idmap-devel-1.16.2-13.el7.ppc64le.rpm
libsss_nss_idmap-devel-1.16.2-13.el7.ppc64le.rpm
libsss_simpleifp-devel-1.16.2-13.el7.ppc64le.rpm
python-libsss_nss_idmap-1.16.2-13.el7.ppc64le.rpm
sssd-debuginfo-1.16.2-13.el7.ppc64le.rpm
sssd-libwbclient-devel-1.16.2-13.el7.ppc64le.rpm

s390x:
libipa_hbac-devel-1.16.2-13.el7.s390.rpm
libipa_hbac-devel-1.16.2-13.el7.s390x.rpm
libsss_certmap-devel-1.16.2-13.el7.s390.rpm
libsss_certmap-devel-1.16.2-13.el7.s390x.rpm
libsss_idmap-devel-1.16.2-13.el7.s390.rpm
libsss_idmap-devel-1.16.2-13.el7.s390x.rpm
libsss_nss_idmap-devel-1.16.2-13.el7.s390.rpm
libsss_nss_idmap-devel-1.16.2-13.el7.s390x.rpm
libsss_simpleifp-devel-1.16.2-13.el7.s390.rpm
libsss_simpleifp-devel-1.16.2-13.el7.s390x.rpm
python-libsss_nss_idmap-1.16.2-13.el7.s390x.rpm
sssd-debuginfo-1.16.2-13.el7.s390.rpm
sssd-debuginfo-1.16.2-13.el7.s390x.rpm
sssd-libwbclient-devel-1.16.2-13.el7.s390.rpm
sssd-libwbclient-devel-1.16.2-13.el7.s390x.rpm

x86_64:
libipa_hbac-devel-1.16.2-13.el7.i686.rpm
libipa_hbac-devel-1.16.2-13.el7.x86_64.rpm
libsss_certmap-devel-1.16.2-13.el7.i686.rpm
libsss_certmap-devel-1.16.2-13.el7.x86_64.rpm
libsss_idmap-devel-1.16.2-13.el7.i686.rpm
libsss_idmap-devel-1.16.2-13.el7.x86_64.rpm
libsss_nss_idmap-devel-1.16.2-13.el7.i686.rpm
libsss_nss_idmap-devel-1.16.2-13.el7.x86_64.rpm
libsss_simpleifp-devel-1.16.2-13.el7.i686.rpm
libsss_simpleifp-devel-1.16.2-13.el7.x86_64.rpm
sssd-debuginfo-1.16.2-13.el7.i686.rpm
sssd-debuginfo-1.16.2-13.el7.x86_64.rpm
sssd-libwbclient-devel-1.16.2-13.el7.i686.rpm
sssd-libwbclient-devel-1.16.2-13.el7.x86_64.rpm

Red Hat Enterprise Linux Workstation (v. 7):

Source:
sssd-1.16.2-13.el7.src.rpm

noarch:
python-sssdconfig-1.16.2-13.el7.noarch.rpm

x86_64:
libipa_hbac-1.16.2-13.el7.i686.rpm
libipa_hbac-1.16.2-13.el7.x86_64.rpm
libsss_autofs-1.16.2-13.el7.x86_64.rpm
libsss_certmap-1.16.2-13.el7.i686.rpm
libsss_certmap-1.16.2-13.el7.x86_64.rpm
libsss_idmap-1.16.2-13.el7.i686.rpm
libsss_idmap-1.16.2-13.el7.x86_64.rpm
libsss_nss_idmap-1.16.2-13.el7.i686.rpm
libsss_nss_idmap-1.16.2-13.el7.x86_64.rpm
libsss_simpleifp-1.16.2-13.el7.i686.rpm
libsss_simpleifp-1.16.2-13.el7.x86_64.rpm
libsss_sudo-1.16.2-13.el7.x86_64.rpm
python-libipa_hbac-1.16.2-13.el7.x86_64.rpm
python-libsss_nss_idmap-1.16.2-13.el7.x86_64.rpm
python-sss-1.16.2-13.el7.x86_64.rpm
python-sss-murmur-1.16.2-13.el7.x86_64.rpm
sssd-1.16.2-13.el7.x86_64.rpm
sssd-ad-1.16.2-13.el7.x86_64.rpm
sssd-client-1.16.2-13.el7.i686.rpm
sssd-client-1.16.2-13.el7.x86_64.rpm
sssd-common-1.16.2-13.el7.x86_64.rpm
sssd-common-pac-1.16.2-13.el7.x86_64.rpm
sssd-dbus-1.16.2-13.el7.x86_64.rpm
sssd-debuginfo-1.16.2-13.el7.i686.rpm
sssd-debuginfo-1.16.2-13.el7.x86_64.rpm
sssd-ipa-1.16.2-13.el7.x86_64.rpm
sssd-kcm-1.16.2-13.el7.x86_64.rpm
sssd-krb5-1.16.2-13.el7.x86_64.rpm
sssd-krb5-common-1.16.2-13.el7.x86_64.rpm
sssd-ldap-1.16.2-13.el7.x86_64.rpm
sssd-libwbclient-1.16.2-13.el7.x86_64.rpm
sssd-polkit-rules-1.16.2-13.el7.x86_64.rpm
sssd-proxy-1.16.2-13.el7.x86_64.rpm
sssd-tools-1.16.2-13.el7.x86_64.rpm
sssd-winbind-idmap-1.16.2-13.el7.x86_64.rpm

Red Hat Enterprise Linux Workstation Optional (v. 7):

x86_64:
libipa_hbac-devel-1.16.2-13.el7.i686.rpm
libipa_hbac-devel-1.16.2-13.el7.x86_64.rpm
libsss_certmap-devel-1.16.2-13.el7.i686.rpm
libsss_certmap-devel-1.16.2-13.el7.x86_64.rpm
libsss_idmap-devel-1.16.2-13.el7.i686.rpm
libsss_idmap-devel-1.16.2-13.el7.x86_64.rpm
libsss_nss_idmap-devel-1.16.2-13.el7.i686.rpm
libsss_nss_idmap-devel-1.16.2-13.el7.x86_64.rpm
libsss_simpleifp-devel-1.16.2-13.el7.i686.rpm
libsss_simpleifp-devel-1.16.2-13.el7.x86_64.rpm
sssd-debuginfo-1.16.2-13.el7.i686.rpm
sssd-debuginfo-1.16.2-13.el7.x86_64.rpm
sssd-libwbclient-devel-1.16.2-13.el7.i686.rpm
sssd-libwbclient-devel-1.16.2-13.el7.x86_64.rpm

These packages are GPG signed by Red Hat for security.  Our key and
details on how to verify the signature are available from
https://access.redhat.com/security/team/key/

7. References:

https://access.redhat.com/security/cve/CVE-2018-10852
https://access.redhat.com/security/updates/classification/#low
https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/7/html/7.6_release_notes/index

8. Contact:

The Red Hat security contact is <secalert@redhat.com>. More contact
details at https://access.redhat.com/security/team/contact/

Copyright 2018 Red Hat, Inc.
- -----BEGIN PGP SIGNATURE-----
Version: GnuPG v1

iQIVAwUBW9gQBtzjgjWX9erEAQhoAA//Vw3B6wv0aGX7sbWYPV4bx67Fl1BokDZq
jBmYEhwGV3MKd+3nP7l+eA+uAPW689eHhksFT6RQPB0NJCOAp8/x1UKLbC47zQQp
IEIvwkSbCohJYlhNE7fpJ5a5A7p1BXfgLv+HKOAnujY+QsaW5bAhqf3MCAe9U+E0
mykM+G/fmoS09v8PC+CQxUDH8x+eaixHGjqyGjvmgYlMDjRrr5ZzFz53gMy5dkLN
vPJ3x4qPTgsjTqs2MgtOtU4qWXKIzCYHZCQwEBB4S6sJl1vmR51guMpZhHa+QYEU
qw0JM0nlGT2jwT5O5IXMa2AdTIseuvJp8liWEtRuHPtxLIVu+THY3ft+zRIhl4Uw
JHxL8FCyt4uatqT5kmqPpUHG09eC2UXG9IJmKZF1SZoufNGN3pi0b44o8COSEH1t
Dp2eOpWfl1HoTd0V3c5M0djAtk4qT2R/z403FLj89XmkniBlU2PtlqJJLyK9rnwO
LGv1WyDdWIfNfeVUu0Vuld5VlLqwNV5u0cqtaR8a2n+o/Y3rQv9HkEH7yAcCiGJv
NRjA/N0nt6MtIsgl/ZiOKevDAvL58p9Ia1dcFIlAcaRU160AMsc71qyWacskn7bI
CN6a5HsqpdDLrXmfQZSfONAiq5lvrfwvEMBWKU7GZdvJ/NKtqAgpUUADurS62RmO
0EJu80uo4cs=
=Hg2/
- -----END PGP SIGNATURE-----

- --------------------------END INCLUDED TEXT--------------------

You have received this e-mail bulletin as a result of your organisation's
registration with AusCERT. The mailing list you are subscribed to is
maintained within your organisation, so if you do not wish to continue
receiving these bulletins you should contact your local IT manager. If
you do not know who that is, please send an email to auscert@auscert.org.au
and we will forward your request to the appropriate person.

NOTE: Third Party Rights
This security bulletin is provided as a service to AusCERT's members.  As
AusCERT did not write the document quoted above, AusCERT has had no control
over its content. The decision to follow or act on information or advice
contained in this security bulletin is the responsibility of each user or
organisation, and should be considered in accordance with your organisation's
site policies and procedures. AusCERT takes no responsibility for consequences
which may arise from following or acting on information or advice contained in
this security bulletin.

NOTE: This is only the original release of the security bulletin.  It may
not be updated when updates to the original are made.  If downloading at
a later date, it is recommended that the bulletin is retrieved directly
from the author's website to ensure that the information is still current.

Contact information for the authors of the original document is included
in the Security Bulletin above.  If you have any questions or need further
information, please contact them directly.

Previous advisories and external security bulletins can be retrieved from:

        https://www.auscert.org.au/bulletins/

===========================================================================
Australian Computer Emergency Response Team
The University of Queensland
Brisbane
Qld 4072

Internet Email: auscert@auscert.org.au
Facsimile:      (07) 3365 7031
Telephone:      (07) 3365 4417 (International: +61 7 3365 4417)
                AusCERT personnel answer during Queensland business hours
                which are GMT+10:00 (AEST).
                On call after hours for member emergencies only.
===========================================================================
-----BEGIN PGP SIGNATURE-----
Comment: http://www.auscert.org.au/render.html?it=1967

iQIVAwUBW9o0NmaOgq3Tt24GAQj6hg//cgRTgR0TeT2cHbJFCF4OOdikNQaeg+bT
hYO96ByIae1iPnq9oDPm7G8ed+BkpI29SeMQ+p4hL+w3buu5AmtNGOEoWqw5LTsc
WM68EOVjdO9zzdE/P7r6Jlo+iz5iy7BE0L+ab7LcPH29W4/G0JNGm+J5Jhoy8eqC
KoKLi+nDLyAuuyQyVmKRsoyNAWuTEJ/XRcwIoJyZWjHwzgMznJHAd6gW2NhZN3YV
5cZGUmWy29kFiDgiZBqeuAOQ2CIJgP64JPorKplghDFYNTLjbxKM0+qVj+7JlAUh
dgsUbT5WmuH3ltKmgf6ROzaXbyvDx8n1cu3yGjKo5BJhaMO4xclJm5KORJwpYEkU
n3atvasY8cwOCeYsEqLwhaDNzfQkWTa4kEaCYNYV9ldhKOZJuUIPYJFjWnG1ESi3
xX7pSSF/XHhoZJQd5SlJ858qr/SopxB6B5IZkX7+evnyFeX9twfjtREibZiFM+f0
binY6oclEYWQfRwkNjD84cr1JOTgDl2B9mMwzFxCu0Z+SGuSCaqWuTnrHDOdH+qI
+GKIkSSLWmpv6Nb2kB9VjnBHyFqccN7yAsipOWhjRv1U0/3EUAo6F99p2GLnCZd0
B4TwDsNL9UzMfRJxklBsN+k7yG5raieq8Ehv73KcZMZ8ZpNOWIRH4eCQEtCfJrF4
KSTBV5BiOXk=
=hECW
-----END PGP SIGNATURE-----