Protect yourself against future threats.
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 =========================================================================== AUSCERT External Security Bulletin Redistribution ESB-2018.3407 Low: sssd security, bug fix, and enhancement update 31 October 2018 =========================================================================== AusCERT Security Bulletin Summary --------------------------------- Product: sssd Publisher: Red Hat Operating System: Red Hat Enterprise Linux Server 7 Red Hat Enterprise Linux WS/Desktop 7 Impact/Access: Access Confidential Data -- Existing Account Resolution: Patch/Upgrade CVE Names: CVE-2018-10852 Reference: ESB-2018.2065 Original Bulletin: https://access.redhat.com/errata/RHSA-2018:3158 - --------------------------BEGIN INCLUDED TEXT-------------------- - -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ===================================================================== Red Hat Security Advisory Synopsis: Low: sssd security, bug fix, and enhancement update Advisory ID: RHSA-2018:3158-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2018:3158 Issue date: 2018-10-30 CVE Names: CVE-2018-10852 ===================================================================== 1. Summary: An update for sssd is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux Client (v. 7) - noarch, x86_64 Red Hat Enterprise Linux Client Optional (v. 7) - x86_64 Red Hat Enterprise Linux ComputeNode (v. 7) - noarch, x86_64 Red Hat Enterprise Linux ComputeNode Optional (v. 7) - x86_64 Red Hat Enterprise Linux Server (v. 7) - noarch, ppc64, ppc64le, s390x, x86_64 Red Hat Enterprise Linux Server Optional (v. 7) - ppc64, ppc64le, s390x, x86_64 Red Hat Enterprise Linux Workstation (v. 7) - noarch, x86_64 Red Hat Enterprise Linux Workstation Optional (v. 7) - x86_64 Red Hat Enterprise Linux for ARM and IBM Power LE (POWER9) Server (v. 7) - aarch64, noarch, ppc64le, s390x Red Hat Enterprise Linux for ARM and IBM Power LE (POWER9) Server Optional (v. 7) - aarch64, ppc64le, s390x 3. Description: The System Security Services Daemon (SSSD) service provides a set of daemons to manage access to remote directories and authentication mechanisms. It also provides the Name Service Switch (NSS) and the Pluggable Authentication Modules (PAM) interfaces toward the system, and a pluggable back-end system to connect to multiple different account sources. The following packages have been upgraded to a later upstream version: sssd (1.16.2). (BZ#1558498) Security Fix(es): * sssd: information leak from the sssd-sudo responder (CVE-2018-10852) For more details about the security issue(s), including the impact, a CVSS score, and other related information, refer to the CVE page(s) listed in the References section. This issue was discovered by Jakub Hrozek (Red Hat). Additional Changes: For detailed information on changes in this release, see the Red Hat Enterprise Linux 7.6 Release Notes linked from the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1385665 - Incorrect error code returned from krb5_child (updated) 1416528 - sssd in cross realm trust configuration should be able to use AD KDCs from a client site defined in sssd.conf or a snippet 1459348 - extend sss-certmap man page regarding priority processing 1509691 - Document how to change the regular expression for SSSD so that group names with an @-sign can be parsed 1514061 - ID override GID from Default Trust View is not properly resolved in case domain resolution order is set 1516266 - Give a more detailed debug and system-log message if krb5_init_context() failed 1522928 - sssd doesn't allow user with expired password to login when PasswordgraceLimit set 1534749 - Requesting an AD user's private group and then the user itself returns an emty homedir 1537272 - SSH public key authentication keeps working after keys are removed from ID view 1537279 - Certificate is not removed from cache when it's removed from the override 1538555 - crash in nss_protocol_fill_netgrent. sssd_nss[19234]: segfault at 80 ip 000055612688c2a0 sp 00007ffddf9b9cd0 error 4 in sssd_nss[55612687e000+39000] 1546754 - The man page of sss_ssh_authorizedkeys can be enhanced to better explain how the keys are retrieved and how X.509 certificates can be used 1558498 - Rebase sssd to the latests upstream release of the 1.16 branch 1562025 - externalUser sudo attribute must be fully-qualified 1565774 - After updating to RHEL 7.5 failing to clear the sssd cache 1566782 - memory management issue in the sssd_nss_ex interface can cause the ns-slapd process on IPA server to crash 1571526 - SSSD with ID provider 'ad' should give a warning in case the ldap schema is manually changed to something different than 'ad'. 1577335 - /usr/libexec/sssd/sssd_autofs SIGABRT crash daily 1578291 - Samba can not register sss idmap module because it's using an outdated SMB_IDMAP_INTERFACE_VERSION 1583251 - home dir disappear in sssd cache on the IPA master for AD users 1583725 - SSSD AD uses LDAP filter to detect POSIX attributes stored in AD GC also for regular AD DC queries 1588810 - CVE-2018-10852 sssd: information leak from the sssd-sudo responder 1600822 - SSSD bails out saving desktop profiles in case an invalid profile is found 1602781 - Offline logins and/or id_provider=local logins fail after upgrade to 7.6 1607313 - When sssd is running as non-root user, the sudo pipe is created as sssd:sssd but then the private pipe ownership fails 1610667 - sssd_ssh leaks file descriptors when more than one certificate is converted into an SSH key 6. Package List: Red Hat Enterprise Linux Client (v. 7): Source: sssd-1.16.2-13.el7.src.rpm noarch: python-sssdconfig-1.16.2-13.el7.noarch.rpm x86_64: libipa_hbac-1.16.2-13.el7.i686.rpm libipa_hbac-1.16.2-13.el7.x86_64.rpm libsss_autofs-1.16.2-13.el7.x86_64.rpm libsss_certmap-1.16.2-13.el7.i686.rpm libsss_certmap-1.16.2-13.el7.x86_64.rpm libsss_idmap-1.16.2-13.el7.i686.rpm libsss_idmap-1.16.2-13.el7.x86_64.rpm libsss_nss_idmap-1.16.2-13.el7.i686.rpm libsss_nss_idmap-1.16.2-13.el7.x86_64.rpm libsss_simpleifp-1.16.2-13.el7.i686.rpm libsss_simpleifp-1.16.2-13.el7.x86_64.rpm libsss_sudo-1.16.2-13.el7.x86_64.rpm python-libipa_hbac-1.16.2-13.el7.x86_64.rpm python-sss-1.16.2-13.el7.x86_64.rpm python-sss-murmur-1.16.2-13.el7.x86_64.rpm sssd-1.16.2-13.el7.x86_64.rpm sssd-ad-1.16.2-13.el7.x86_64.rpm sssd-client-1.16.2-13.el7.i686.rpm sssd-client-1.16.2-13.el7.x86_64.rpm sssd-common-1.16.2-13.el7.x86_64.rpm sssd-common-pac-1.16.2-13.el7.x86_64.rpm sssd-dbus-1.16.2-13.el7.x86_64.rpm sssd-debuginfo-1.16.2-13.el7.i686.rpm sssd-debuginfo-1.16.2-13.el7.x86_64.rpm sssd-ipa-1.16.2-13.el7.x86_64.rpm sssd-kcm-1.16.2-13.el7.x86_64.rpm sssd-krb5-1.16.2-13.el7.x86_64.rpm sssd-krb5-common-1.16.2-13.el7.x86_64.rpm sssd-ldap-1.16.2-13.el7.x86_64.rpm sssd-libwbclient-1.16.2-13.el7.x86_64.rpm sssd-polkit-rules-1.16.2-13.el7.x86_64.rpm sssd-proxy-1.16.2-13.el7.x86_64.rpm sssd-tools-1.16.2-13.el7.x86_64.rpm sssd-winbind-idmap-1.16.2-13.el7.x86_64.rpm Red Hat Enterprise Linux Client Optional (v. 7): x86_64: libipa_hbac-devel-1.16.2-13.el7.i686.rpm libipa_hbac-devel-1.16.2-13.el7.x86_64.rpm libsss_certmap-devel-1.16.2-13.el7.i686.rpm libsss_certmap-devel-1.16.2-13.el7.x86_64.rpm libsss_idmap-devel-1.16.2-13.el7.i686.rpm libsss_idmap-devel-1.16.2-13.el7.x86_64.rpm libsss_nss_idmap-devel-1.16.2-13.el7.i686.rpm libsss_nss_idmap-devel-1.16.2-13.el7.x86_64.rpm libsss_simpleifp-devel-1.16.2-13.el7.i686.rpm libsss_simpleifp-devel-1.16.2-13.el7.x86_64.rpm python-libsss_nss_idmap-1.16.2-13.el7.x86_64.rpm sssd-debuginfo-1.16.2-13.el7.i686.rpm sssd-debuginfo-1.16.2-13.el7.x86_64.rpm sssd-libwbclient-devel-1.16.2-13.el7.i686.rpm sssd-libwbclient-devel-1.16.2-13.el7.x86_64.rpm Red Hat Enterprise Linux ComputeNode (v. 7): Source: sssd-1.16.2-13.el7.src.rpm noarch: python-sssdconfig-1.16.2-13.el7.noarch.rpm x86_64: libipa_hbac-1.16.2-13.el7.i686.rpm libipa_hbac-1.16.2-13.el7.x86_64.rpm libsss_autofs-1.16.2-13.el7.x86_64.rpm libsss_certmap-1.16.2-13.el7.i686.rpm libsss_certmap-1.16.2-13.el7.x86_64.rpm libsss_idmap-1.16.2-13.el7.i686.rpm libsss_idmap-1.16.2-13.el7.x86_64.rpm libsss_nss_idmap-1.16.2-13.el7.i686.rpm libsss_nss_idmap-1.16.2-13.el7.x86_64.rpm libsss_simpleifp-1.16.2-13.el7.i686.rpm libsss_simpleifp-1.16.2-13.el7.x86_64.rpm libsss_sudo-1.16.2-13.el7.x86_64.rpm python-libipa_hbac-1.16.2-13.el7.x86_64.rpm python-sss-1.16.2-13.el7.x86_64.rpm python-sss-murmur-1.16.2-13.el7.x86_64.rpm sssd-1.16.2-13.el7.x86_64.rpm sssd-ad-1.16.2-13.el7.x86_64.rpm sssd-client-1.16.2-13.el7.i686.rpm sssd-client-1.16.2-13.el7.x86_64.rpm sssd-common-1.16.2-13.el7.x86_64.rpm sssd-common-pac-1.16.2-13.el7.x86_64.rpm sssd-dbus-1.16.2-13.el7.x86_64.rpm sssd-debuginfo-1.16.2-13.el7.i686.rpm sssd-debuginfo-1.16.2-13.el7.x86_64.rpm sssd-ipa-1.16.2-13.el7.x86_64.rpm sssd-kcm-1.16.2-13.el7.x86_64.rpm sssd-krb5-1.16.2-13.el7.x86_64.rpm sssd-krb5-common-1.16.2-13.el7.x86_64.rpm sssd-ldap-1.16.2-13.el7.x86_64.rpm sssd-libwbclient-1.16.2-13.el7.x86_64.rpm sssd-polkit-rules-1.16.2-13.el7.x86_64.rpm sssd-proxy-1.16.2-13.el7.x86_64.rpm sssd-tools-1.16.2-13.el7.x86_64.rpm sssd-winbind-idmap-1.16.2-13.el7.x86_64.rpm Red Hat Enterprise Linux ComputeNode Optional (v. 7): x86_64: libipa_hbac-devel-1.16.2-13.el7.i686.rpm libipa_hbac-devel-1.16.2-13.el7.x86_64.rpm libsss_certmap-devel-1.16.2-13.el7.i686.rpm libsss_certmap-devel-1.16.2-13.el7.x86_64.rpm libsss_idmap-devel-1.16.2-13.el7.i686.rpm libsss_idmap-devel-1.16.2-13.el7.x86_64.rpm libsss_nss_idmap-devel-1.16.2-13.el7.i686.rpm libsss_nss_idmap-devel-1.16.2-13.el7.x86_64.rpm libsss_simpleifp-devel-1.16.2-13.el7.i686.rpm libsss_simpleifp-devel-1.16.2-13.el7.x86_64.rpm python-libsss_nss_idmap-1.16.2-13.el7.x86_64.rpm sssd-debuginfo-1.16.2-13.el7.i686.rpm sssd-debuginfo-1.16.2-13.el7.x86_64.rpm sssd-libwbclient-devel-1.16.2-13.el7.i686.rpm sssd-libwbclient-devel-1.16.2-13.el7.x86_64.rpm Red Hat Enterprise Linux Server (v. 7): Source: sssd-1.16.2-13.el7.src.rpm noarch: python-sssdconfig-1.16.2-13.el7.noarch.rpm ppc64: libipa_hbac-1.16.2-13.el7.ppc.rpm libipa_hbac-1.16.2-13.el7.ppc64.rpm libsss_autofs-1.16.2-13.el7.ppc64.rpm libsss_certmap-1.16.2-13.el7.ppc.rpm libsss_certmap-1.16.2-13.el7.ppc64.rpm libsss_idmap-1.16.2-13.el7.ppc.rpm libsss_idmap-1.16.2-13.el7.ppc64.rpm libsss_nss_idmap-1.16.2-13.el7.ppc.rpm libsss_nss_idmap-1.16.2-13.el7.ppc64.rpm libsss_simpleifp-1.16.2-13.el7.ppc.rpm libsss_simpleifp-1.16.2-13.el7.ppc64.rpm libsss_sudo-1.16.2-13.el7.ppc64.rpm python-libipa_hbac-1.16.2-13.el7.ppc64.rpm python-sss-1.16.2-13.el7.ppc64.rpm python-sss-murmur-1.16.2-13.el7.ppc64.rpm sssd-1.16.2-13.el7.ppc64.rpm sssd-ad-1.16.2-13.el7.ppc64.rpm sssd-client-1.16.2-13.el7.ppc.rpm sssd-client-1.16.2-13.el7.ppc64.rpm sssd-common-1.16.2-13.el7.ppc64.rpm sssd-common-pac-1.16.2-13.el7.ppc64.rpm sssd-dbus-1.16.2-13.el7.ppc64.rpm sssd-debuginfo-1.16.2-13.el7.ppc.rpm sssd-debuginfo-1.16.2-13.el7.ppc64.rpm sssd-ipa-1.16.2-13.el7.ppc64.rpm sssd-kcm-1.16.2-13.el7.ppc64.rpm sssd-krb5-1.16.2-13.el7.ppc64.rpm sssd-krb5-common-1.16.2-13.el7.ppc64.rpm sssd-ldap-1.16.2-13.el7.ppc64.rpm sssd-libwbclient-1.16.2-13.el7.ppc64.rpm sssd-polkit-rules-1.16.2-13.el7.ppc64.rpm sssd-proxy-1.16.2-13.el7.ppc64.rpm sssd-tools-1.16.2-13.el7.ppc64.rpm sssd-winbind-idmap-1.16.2-13.el7.ppc64.rpm ppc64le: libipa_hbac-1.16.2-13.el7.ppc64le.rpm libsss_autofs-1.16.2-13.el7.ppc64le.rpm libsss_certmap-1.16.2-13.el7.ppc64le.rpm libsss_idmap-1.16.2-13.el7.ppc64le.rpm libsss_nss_idmap-1.16.2-13.el7.ppc64le.rpm libsss_simpleifp-1.16.2-13.el7.ppc64le.rpm libsss_sudo-1.16.2-13.el7.ppc64le.rpm python-libipa_hbac-1.16.2-13.el7.ppc64le.rpm python-sss-1.16.2-13.el7.ppc64le.rpm python-sss-murmur-1.16.2-13.el7.ppc64le.rpm sssd-1.16.2-13.el7.ppc64le.rpm sssd-ad-1.16.2-13.el7.ppc64le.rpm sssd-client-1.16.2-13.el7.ppc64le.rpm sssd-common-1.16.2-13.el7.ppc64le.rpm sssd-common-pac-1.16.2-13.el7.ppc64le.rpm sssd-dbus-1.16.2-13.el7.ppc64le.rpm sssd-debuginfo-1.16.2-13.el7.ppc64le.rpm sssd-ipa-1.16.2-13.el7.ppc64le.rpm sssd-kcm-1.16.2-13.el7.ppc64le.rpm sssd-krb5-1.16.2-13.el7.ppc64le.rpm sssd-krb5-common-1.16.2-13.el7.ppc64le.rpm sssd-ldap-1.16.2-13.el7.ppc64le.rpm sssd-libwbclient-1.16.2-13.el7.ppc64le.rpm sssd-polkit-rules-1.16.2-13.el7.ppc64le.rpm sssd-proxy-1.16.2-13.el7.ppc64le.rpm sssd-tools-1.16.2-13.el7.ppc64le.rpm sssd-winbind-idmap-1.16.2-13.el7.ppc64le.rpm s390x: libipa_hbac-1.16.2-13.el7.s390.rpm libipa_hbac-1.16.2-13.el7.s390x.rpm libsss_autofs-1.16.2-13.el7.s390x.rpm libsss_certmap-1.16.2-13.el7.s390.rpm libsss_certmap-1.16.2-13.el7.s390x.rpm libsss_idmap-1.16.2-13.el7.s390.rpm libsss_idmap-1.16.2-13.el7.s390x.rpm libsss_nss_idmap-1.16.2-13.el7.s390.rpm libsss_nss_idmap-1.16.2-13.el7.s390x.rpm libsss_simpleifp-1.16.2-13.el7.s390.rpm libsss_simpleifp-1.16.2-13.el7.s390x.rpm libsss_sudo-1.16.2-13.el7.s390x.rpm python-libipa_hbac-1.16.2-13.el7.s390x.rpm python-sss-1.16.2-13.el7.s390x.rpm python-sss-murmur-1.16.2-13.el7.s390x.rpm sssd-1.16.2-13.el7.s390x.rpm sssd-ad-1.16.2-13.el7.s390x.rpm sssd-client-1.16.2-13.el7.s390.rpm sssd-client-1.16.2-13.el7.s390x.rpm sssd-common-1.16.2-13.el7.s390x.rpm sssd-common-pac-1.16.2-13.el7.s390x.rpm sssd-dbus-1.16.2-13.el7.s390x.rpm sssd-debuginfo-1.16.2-13.el7.s390.rpm sssd-debuginfo-1.16.2-13.el7.s390x.rpm sssd-ipa-1.16.2-13.el7.s390x.rpm sssd-kcm-1.16.2-13.el7.s390x.rpm sssd-krb5-1.16.2-13.el7.s390x.rpm sssd-krb5-common-1.16.2-13.el7.s390x.rpm sssd-ldap-1.16.2-13.el7.s390x.rpm sssd-libwbclient-1.16.2-13.el7.s390x.rpm sssd-polkit-rules-1.16.2-13.el7.s390x.rpm sssd-proxy-1.16.2-13.el7.s390x.rpm sssd-tools-1.16.2-13.el7.s390x.rpm sssd-winbind-idmap-1.16.2-13.el7.s390x.rpm x86_64: libipa_hbac-1.16.2-13.el7.i686.rpm libipa_hbac-1.16.2-13.el7.x86_64.rpm libsss_autofs-1.16.2-13.el7.x86_64.rpm libsss_certmap-1.16.2-13.el7.i686.rpm libsss_certmap-1.16.2-13.el7.x86_64.rpm libsss_idmap-1.16.2-13.el7.i686.rpm libsss_idmap-1.16.2-13.el7.x86_64.rpm libsss_nss_idmap-1.16.2-13.el7.i686.rpm libsss_nss_idmap-1.16.2-13.el7.x86_64.rpm libsss_simpleifp-1.16.2-13.el7.i686.rpm libsss_simpleifp-1.16.2-13.el7.x86_64.rpm libsss_sudo-1.16.2-13.el7.x86_64.rpm python-libipa_hbac-1.16.2-13.el7.x86_64.rpm python-libsss_nss_idmap-1.16.2-13.el7.x86_64.rpm python-sss-1.16.2-13.el7.x86_64.rpm python-sss-murmur-1.16.2-13.el7.x86_64.rpm sssd-1.16.2-13.el7.x86_64.rpm sssd-ad-1.16.2-13.el7.x86_64.rpm sssd-client-1.16.2-13.el7.i686.rpm sssd-client-1.16.2-13.el7.x86_64.rpm sssd-common-1.16.2-13.el7.x86_64.rpm sssd-common-pac-1.16.2-13.el7.x86_64.rpm sssd-dbus-1.16.2-13.el7.x86_64.rpm sssd-debuginfo-1.16.2-13.el7.i686.rpm sssd-debuginfo-1.16.2-13.el7.x86_64.rpm sssd-ipa-1.16.2-13.el7.x86_64.rpm sssd-kcm-1.16.2-13.el7.x86_64.rpm sssd-krb5-1.16.2-13.el7.x86_64.rpm sssd-krb5-common-1.16.2-13.el7.x86_64.rpm sssd-ldap-1.16.2-13.el7.x86_64.rpm sssd-libwbclient-1.16.2-13.el7.x86_64.rpm sssd-polkit-rules-1.16.2-13.el7.x86_64.rpm sssd-proxy-1.16.2-13.el7.x86_64.rpm sssd-tools-1.16.2-13.el7.x86_64.rpm sssd-winbind-idmap-1.16.2-13.el7.x86_64.rpm Red Hat Enterprise Linux for ARM and IBM Power LE (POWER9) Server (v. 7): Source: sssd-1.16.2-13.el7.src.rpm aarch64: libipa_hbac-1.16.2-13.el7.aarch64.rpm libsss_autofs-1.16.2-13.el7.aarch64.rpm libsss_certmap-1.16.2-13.el7.aarch64.rpm libsss_idmap-1.16.2-13.el7.aarch64.rpm libsss_nss_idmap-1.16.2-13.el7.aarch64.rpm libsss_simpleifp-1.16.2-13.el7.aarch64.rpm libsss_sudo-1.16.2-13.el7.aarch64.rpm python-libipa_hbac-1.16.2-13.el7.aarch64.rpm python-libsss_nss_idmap-1.16.2-13.el7.aarch64.rpm python-sss-1.16.2-13.el7.aarch64.rpm python-sss-murmur-1.16.2-13.el7.aarch64.rpm sssd-1.16.2-13.el7.aarch64.rpm sssd-ad-1.16.2-13.el7.aarch64.rpm sssd-client-1.16.2-13.el7.aarch64.rpm sssd-common-1.16.2-13.el7.aarch64.rpm sssd-common-pac-1.16.2-13.el7.aarch64.rpm sssd-dbus-1.16.2-13.el7.aarch64.rpm sssd-debuginfo-1.16.2-13.el7.aarch64.rpm sssd-ipa-1.16.2-13.el7.aarch64.rpm sssd-kcm-1.16.2-13.el7.aarch64.rpm sssd-krb5-1.16.2-13.el7.aarch64.rpm sssd-krb5-common-1.16.2-13.el7.aarch64.rpm sssd-ldap-1.16.2-13.el7.aarch64.rpm sssd-libwbclient-1.16.2-13.el7.aarch64.rpm sssd-polkit-rules-1.16.2-13.el7.aarch64.rpm sssd-proxy-1.16.2-13.el7.aarch64.rpm sssd-tools-1.16.2-13.el7.aarch64.rpm sssd-winbind-idmap-1.16.2-13.el7.aarch64.rpm noarch: python-sssdconfig-1.16.2-13.el7.noarch.rpm ppc64le: libipa_hbac-1.16.2-13.el7.ppc64le.rpm libsss_autofs-1.16.2-13.el7.ppc64le.rpm libsss_certmap-1.16.2-13.el7.ppc64le.rpm libsss_idmap-1.16.2-13.el7.ppc64le.rpm libsss_nss_idmap-1.16.2-13.el7.ppc64le.rpm libsss_simpleifp-1.16.2-13.el7.ppc64le.rpm libsss_sudo-1.16.2-13.el7.ppc64le.rpm python-libipa_hbac-1.16.2-13.el7.ppc64le.rpm python-sss-1.16.2-13.el7.ppc64le.rpm python-sss-murmur-1.16.2-13.el7.ppc64le.rpm sssd-1.16.2-13.el7.ppc64le.rpm sssd-ad-1.16.2-13.el7.ppc64le.rpm sssd-client-1.16.2-13.el7.ppc64le.rpm sssd-common-1.16.2-13.el7.ppc64le.rpm sssd-common-pac-1.16.2-13.el7.ppc64le.rpm sssd-dbus-1.16.2-13.el7.ppc64le.rpm sssd-debuginfo-1.16.2-13.el7.ppc64le.rpm sssd-ipa-1.16.2-13.el7.ppc64le.rpm sssd-kcm-1.16.2-13.el7.ppc64le.rpm sssd-krb5-1.16.2-13.el7.ppc64le.rpm sssd-krb5-common-1.16.2-13.el7.ppc64le.rpm sssd-ldap-1.16.2-13.el7.ppc64le.rpm sssd-libwbclient-1.16.2-13.el7.ppc64le.rpm sssd-polkit-rules-1.16.2-13.el7.ppc64le.rpm sssd-proxy-1.16.2-13.el7.ppc64le.rpm sssd-tools-1.16.2-13.el7.ppc64le.rpm sssd-winbind-idmap-1.16.2-13.el7.ppc64le.rpm s390x: libipa_hbac-1.16.2-13.el7.s390.rpm libipa_hbac-1.16.2-13.el7.s390x.rpm libsss_autofs-1.16.2-13.el7.s390x.rpm libsss_certmap-1.16.2-13.el7.s390.rpm libsss_certmap-1.16.2-13.el7.s390x.rpm libsss_idmap-1.16.2-13.el7.s390.rpm libsss_idmap-1.16.2-13.el7.s390x.rpm libsss_nss_idmap-1.16.2-13.el7.s390.rpm libsss_nss_idmap-1.16.2-13.el7.s390x.rpm libsss_simpleifp-1.16.2-13.el7.s390.rpm libsss_simpleifp-1.16.2-13.el7.s390x.rpm libsss_sudo-1.16.2-13.el7.s390x.rpm python-libipa_hbac-1.16.2-13.el7.s390x.rpm python-sss-1.16.2-13.el7.s390x.rpm python-sss-murmur-1.16.2-13.el7.s390x.rpm sssd-1.16.2-13.el7.s390x.rpm sssd-ad-1.16.2-13.el7.s390x.rpm sssd-client-1.16.2-13.el7.s390.rpm sssd-client-1.16.2-13.el7.s390x.rpm sssd-common-1.16.2-13.el7.s390x.rpm sssd-common-pac-1.16.2-13.el7.s390x.rpm sssd-dbus-1.16.2-13.el7.s390x.rpm sssd-debuginfo-1.16.2-13.el7.s390.rpm sssd-debuginfo-1.16.2-13.el7.s390x.rpm sssd-ipa-1.16.2-13.el7.s390x.rpm sssd-kcm-1.16.2-13.el7.s390x.rpm sssd-krb5-1.16.2-13.el7.s390x.rpm sssd-krb5-common-1.16.2-13.el7.s390x.rpm sssd-ldap-1.16.2-13.el7.s390x.rpm sssd-libwbclient-1.16.2-13.el7.s390x.rpm sssd-polkit-rules-1.16.2-13.el7.s390x.rpm sssd-proxy-1.16.2-13.el7.s390x.rpm sssd-tools-1.16.2-13.el7.s390x.rpm sssd-winbind-idmap-1.16.2-13.el7.s390x.rpm Red Hat Enterprise Linux for ARM and IBM Power LE (POWER9) Server Optional (v. 7): aarch64: libipa_hbac-devel-1.16.2-13.el7.aarch64.rpm libsss_certmap-devel-1.16.2-13.el7.aarch64.rpm libsss_idmap-devel-1.16.2-13.el7.aarch64.rpm libsss_nss_idmap-devel-1.16.2-13.el7.aarch64.rpm libsss_simpleifp-devel-1.16.2-13.el7.aarch64.rpm sssd-debuginfo-1.16.2-13.el7.aarch64.rpm sssd-libwbclient-devel-1.16.2-13.el7.aarch64.rpm ppc64le: libipa_hbac-devel-1.16.2-13.el7.ppc64le.rpm libsss_certmap-devel-1.16.2-13.el7.ppc64le.rpm libsss_idmap-devel-1.16.2-13.el7.ppc64le.rpm libsss_nss_idmap-devel-1.16.2-13.el7.ppc64le.rpm libsss_simpleifp-devel-1.16.2-13.el7.ppc64le.rpm python-libsss_nss_idmap-1.16.2-13.el7.ppc64le.rpm sssd-debuginfo-1.16.2-13.el7.ppc64le.rpm sssd-libwbclient-devel-1.16.2-13.el7.ppc64le.rpm s390x: libipa_hbac-devel-1.16.2-13.el7.s390.rpm libipa_hbac-devel-1.16.2-13.el7.s390x.rpm libsss_certmap-devel-1.16.2-13.el7.s390.rpm libsss_certmap-devel-1.16.2-13.el7.s390x.rpm libsss_idmap-devel-1.16.2-13.el7.s390.rpm libsss_idmap-devel-1.16.2-13.el7.s390x.rpm libsss_nss_idmap-devel-1.16.2-13.el7.s390.rpm libsss_nss_idmap-devel-1.16.2-13.el7.s390x.rpm libsss_simpleifp-devel-1.16.2-13.el7.s390.rpm libsss_simpleifp-devel-1.16.2-13.el7.s390x.rpm python-libsss_nss_idmap-1.16.2-13.el7.s390x.rpm sssd-debuginfo-1.16.2-13.el7.s390.rpm sssd-debuginfo-1.16.2-13.el7.s390x.rpm sssd-libwbclient-devel-1.16.2-13.el7.s390.rpm sssd-libwbclient-devel-1.16.2-13.el7.s390x.rpm Red Hat Enterprise Linux Server Optional (v. 7): ppc64: libipa_hbac-devel-1.16.2-13.el7.ppc.rpm libipa_hbac-devel-1.16.2-13.el7.ppc64.rpm libsss_certmap-devel-1.16.2-13.el7.ppc.rpm libsss_certmap-devel-1.16.2-13.el7.ppc64.rpm libsss_idmap-devel-1.16.2-13.el7.ppc.rpm libsss_idmap-devel-1.16.2-13.el7.ppc64.rpm libsss_nss_idmap-devel-1.16.2-13.el7.ppc.rpm libsss_nss_idmap-devel-1.16.2-13.el7.ppc64.rpm libsss_simpleifp-devel-1.16.2-13.el7.ppc.rpm libsss_simpleifp-devel-1.16.2-13.el7.ppc64.rpm python-libsss_nss_idmap-1.16.2-13.el7.ppc64.rpm sssd-debuginfo-1.16.2-13.el7.ppc.rpm sssd-debuginfo-1.16.2-13.el7.ppc64.rpm sssd-libwbclient-devel-1.16.2-13.el7.ppc.rpm sssd-libwbclient-devel-1.16.2-13.el7.ppc64.rpm ppc64le: libipa_hbac-devel-1.16.2-13.el7.ppc64le.rpm libsss_certmap-devel-1.16.2-13.el7.ppc64le.rpm libsss_idmap-devel-1.16.2-13.el7.ppc64le.rpm libsss_nss_idmap-devel-1.16.2-13.el7.ppc64le.rpm libsss_simpleifp-devel-1.16.2-13.el7.ppc64le.rpm python-libsss_nss_idmap-1.16.2-13.el7.ppc64le.rpm sssd-debuginfo-1.16.2-13.el7.ppc64le.rpm sssd-libwbclient-devel-1.16.2-13.el7.ppc64le.rpm s390x: libipa_hbac-devel-1.16.2-13.el7.s390.rpm libipa_hbac-devel-1.16.2-13.el7.s390x.rpm libsss_certmap-devel-1.16.2-13.el7.s390.rpm libsss_certmap-devel-1.16.2-13.el7.s390x.rpm libsss_idmap-devel-1.16.2-13.el7.s390.rpm libsss_idmap-devel-1.16.2-13.el7.s390x.rpm libsss_nss_idmap-devel-1.16.2-13.el7.s390.rpm libsss_nss_idmap-devel-1.16.2-13.el7.s390x.rpm libsss_simpleifp-devel-1.16.2-13.el7.s390.rpm libsss_simpleifp-devel-1.16.2-13.el7.s390x.rpm python-libsss_nss_idmap-1.16.2-13.el7.s390x.rpm sssd-debuginfo-1.16.2-13.el7.s390.rpm sssd-debuginfo-1.16.2-13.el7.s390x.rpm sssd-libwbclient-devel-1.16.2-13.el7.s390.rpm sssd-libwbclient-devel-1.16.2-13.el7.s390x.rpm x86_64: libipa_hbac-devel-1.16.2-13.el7.i686.rpm libipa_hbac-devel-1.16.2-13.el7.x86_64.rpm libsss_certmap-devel-1.16.2-13.el7.i686.rpm libsss_certmap-devel-1.16.2-13.el7.x86_64.rpm libsss_idmap-devel-1.16.2-13.el7.i686.rpm libsss_idmap-devel-1.16.2-13.el7.x86_64.rpm libsss_nss_idmap-devel-1.16.2-13.el7.i686.rpm libsss_nss_idmap-devel-1.16.2-13.el7.x86_64.rpm libsss_simpleifp-devel-1.16.2-13.el7.i686.rpm libsss_simpleifp-devel-1.16.2-13.el7.x86_64.rpm sssd-debuginfo-1.16.2-13.el7.i686.rpm sssd-debuginfo-1.16.2-13.el7.x86_64.rpm sssd-libwbclient-devel-1.16.2-13.el7.i686.rpm sssd-libwbclient-devel-1.16.2-13.el7.x86_64.rpm Red Hat Enterprise Linux Workstation (v. 7): Source: sssd-1.16.2-13.el7.src.rpm noarch: python-sssdconfig-1.16.2-13.el7.noarch.rpm x86_64: libipa_hbac-1.16.2-13.el7.i686.rpm libipa_hbac-1.16.2-13.el7.x86_64.rpm libsss_autofs-1.16.2-13.el7.x86_64.rpm libsss_certmap-1.16.2-13.el7.i686.rpm libsss_certmap-1.16.2-13.el7.x86_64.rpm libsss_idmap-1.16.2-13.el7.i686.rpm libsss_idmap-1.16.2-13.el7.x86_64.rpm libsss_nss_idmap-1.16.2-13.el7.i686.rpm libsss_nss_idmap-1.16.2-13.el7.x86_64.rpm libsss_simpleifp-1.16.2-13.el7.i686.rpm libsss_simpleifp-1.16.2-13.el7.x86_64.rpm libsss_sudo-1.16.2-13.el7.x86_64.rpm python-libipa_hbac-1.16.2-13.el7.x86_64.rpm python-libsss_nss_idmap-1.16.2-13.el7.x86_64.rpm python-sss-1.16.2-13.el7.x86_64.rpm python-sss-murmur-1.16.2-13.el7.x86_64.rpm sssd-1.16.2-13.el7.x86_64.rpm sssd-ad-1.16.2-13.el7.x86_64.rpm sssd-client-1.16.2-13.el7.i686.rpm sssd-client-1.16.2-13.el7.x86_64.rpm sssd-common-1.16.2-13.el7.x86_64.rpm sssd-common-pac-1.16.2-13.el7.x86_64.rpm sssd-dbus-1.16.2-13.el7.x86_64.rpm sssd-debuginfo-1.16.2-13.el7.i686.rpm sssd-debuginfo-1.16.2-13.el7.x86_64.rpm sssd-ipa-1.16.2-13.el7.x86_64.rpm sssd-kcm-1.16.2-13.el7.x86_64.rpm sssd-krb5-1.16.2-13.el7.x86_64.rpm sssd-krb5-common-1.16.2-13.el7.x86_64.rpm sssd-ldap-1.16.2-13.el7.x86_64.rpm sssd-libwbclient-1.16.2-13.el7.x86_64.rpm sssd-polkit-rules-1.16.2-13.el7.x86_64.rpm sssd-proxy-1.16.2-13.el7.x86_64.rpm sssd-tools-1.16.2-13.el7.x86_64.rpm sssd-winbind-idmap-1.16.2-13.el7.x86_64.rpm Red Hat Enterprise Linux Workstation Optional (v. 7): x86_64: libipa_hbac-devel-1.16.2-13.el7.i686.rpm libipa_hbac-devel-1.16.2-13.el7.x86_64.rpm libsss_certmap-devel-1.16.2-13.el7.i686.rpm libsss_certmap-devel-1.16.2-13.el7.x86_64.rpm libsss_idmap-devel-1.16.2-13.el7.i686.rpm libsss_idmap-devel-1.16.2-13.el7.x86_64.rpm libsss_nss_idmap-devel-1.16.2-13.el7.i686.rpm libsss_nss_idmap-devel-1.16.2-13.el7.x86_64.rpm libsss_simpleifp-devel-1.16.2-13.el7.i686.rpm libsss_simpleifp-devel-1.16.2-13.el7.x86_64.rpm sssd-debuginfo-1.16.2-13.el7.i686.rpm sssd-debuginfo-1.16.2-13.el7.x86_64.rpm sssd-libwbclient-devel-1.16.2-13.el7.i686.rpm sssd-libwbclient-devel-1.16.2-13.el7.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2018-10852 https://access.redhat.com/security/updates/classification/#low https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/7/html/7.6_release_notes/index 8. Contact: The Red Hat security contact is <secalert@redhat.com>. More contact details at https://access.redhat.com/security/team/contact/ Copyright 2018 Red Hat, Inc. - -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBW9gQBtzjgjWX9erEAQhoAA//Vw3B6wv0aGX7sbWYPV4bx67Fl1BokDZq jBmYEhwGV3MKd+3nP7l+eA+uAPW689eHhksFT6RQPB0NJCOAp8/x1UKLbC47zQQp IEIvwkSbCohJYlhNE7fpJ5a5A7p1BXfgLv+HKOAnujY+QsaW5bAhqf3MCAe9U+E0 mykM+G/fmoS09v8PC+CQxUDH8x+eaixHGjqyGjvmgYlMDjRrr5ZzFz53gMy5dkLN vPJ3x4qPTgsjTqs2MgtOtU4qWXKIzCYHZCQwEBB4S6sJl1vmR51guMpZhHa+QYEU qw0JM0nlGT2jwT5O5IXMa2AdTIseuvJp8liWEtRuHPtxLIVu+THY3ft+zRIhl4Uw JHxL8FCyt4uatqT5kmqPpUHG09eC2UXG9IJmKZF1SZoufNGN3pi0b44o8COSEH1t Dp2eOpWfl1HoTd0V3c5M0djAtk4qT2R/z403FLj89XmkniBlU2PtlqJJLyK9rnwO LGv1WyDdWIfNfeVUu0Vuld5VlLqwNV5u0cqtaR8a2n+o/Y3rQv9HkEH7yAcCiGJv NRjA/N0nt6MtIsgl/ZiOKevDAvL58p9Ia1dcFIlAcaRU160AMsc71qyWacskn7bI CN6a5HsqpdDLrXmfQZSfONAiq5lvrfwvEMBWKU7GZdvJ/NKtqAgpUUADurS62RmO 0EJu80uo4cs= =Hg2/ - -----END PGP SIGNATURE----- - --------------------------END INCLUDED TEXT-------------------- You have received this e-mail bulletin as a result of your organisation's registration with AusCERT. The mailing list you are subscribed to is maintained within your organisation, so if you do not wish to continue receiving these bulletins you should contact your local IT manager. If you do not know who that is, please send an email to auscert@auscert.org.au and we will forward your request to the appropriate person. NOTE: Third Party Rights This security bulletin is provided as a service to AusCERT's members. As AusCERT did not write the document quoted above, AusCERT has had no control over its content. The decision to follow or act on information or advice contained in this security bulletin is the responsibility of each user or organisation, and should be considered in accordance with your organisation's site policies and procedures. AusCERT takes no responsibility for consequences which may arise from following or acting on information or advice contained in this security bulletin. NOTE: This is only the original release of the security bulletin. It may not be updated when updates to the original are made. If downloading at a later date, it is recommended that the bulletin is retrieved directly from the author's website to ensure that the information is still current. Contact information for the authors of the original document is included in the Security Bulletin above. If you have any questions or need further information, please contact them directly. Previous advisories and external security bulletins can be retrieved from: https://www.auscert.org.au/bulletins/ =========================================================================== Australian Computer Emergency Response Team The University of Queensland Brisbane Qld 4072 Internet Email: auscert@auscert.org.au Facsimile: (07) 3365 7031 Telephone: (07) 3365 4417 (International: +61 7 3365 4417) AusCERT personnel answer during Queensland business hours which are GMT+10:00 (AEST). On call after hours for member emergencies only. =========================================================================== -----BEGIN PGP SIGNATURE----- Comment: http://www.auscert.org.au/render.html?it=1967 iQIVAwUBW9o0NmaOgq3Tt24GAQj6hg//cgRTgR0TeT2cHbJFCF4OOdikNQaeg+bT hYO96ByIae1iPnq9oDPm7G8ed+BkpI29SeMQ+p4hL+w3buu5AmtNGOEoWqw5LTsc WM68EOVjdO9zzdE/P7r6Jlo+iz5iy7BE0L+ab7LcPH29W4/G0JNGm+J5Jhoy8eqC KoKLi+nDLyAuuyQyVmKRsoyNAWuTEJ/XRcwIoJyZWjHwzgMznJHAd6gW2NhZN3YV 5cZGUmWy29kFiDgiZBqeuAOQ2CIJgP64JPorKplghDFYNTLjbxKM0+qVj+7JlAUh dgsUbT5WmuH3ltKmgf6ROzaXbyvDx8n1cu3yGjKo5BJhaMO4xclJm5KORJwpYEkU n3atvasY8cwOCeYsEqLwhaDNzfQkWTa4kEaCYNYV9ldhKOZJuUIPYJFjWnG1ESi3 xX7pSSF/XHhoZJQd5SlJ858qr/SopxB6B5IZkX7+evnyFeX9twfjtREibZiFM+f0 binY6oclEYWQfRwkNjD84cr1JOTgDl2B9mMwzFxCu0Z+SGuSCaqWuTnrHDOdH+qI +GKIkSSLWmpv6Nb2kB9VjnBHyFqccN7yAsipOWhjRv1U0/3EUAo6F99p2GLnCZd0 B4TwDsNL9UzMfRJxklBsN+k7yG5raieq8Ehv73KcZMZ8ZpNOWIRH4eCQEtCfJrF4 KSTBV5BiOXk= =hECW -----END PGP SIGNATURE-----