CVE-2015-5292

Impact:
Low
Public Date:
2015-09-23
CWE:
CWE-401
Bugzilla:
1267580: CVE-2015-5292 sssd: memory leak in the sssd_pac_plugin
It was found that SSSD's Privilege Attribute Certificate (PAC) responder plug-in would leak a small amount of memory on each authentication request. A remote attacker could potentially use this flaw to exhaust all available memory on the system by making repeated requests to a Kerberized daemon application configured to authenticate using the PAC responder plug-in.

Find out more about CVE-2015-5292 from the MITRE CVE dictionary dictionary and NIST NVD.

CVSS v2 metrics

Base Score 2.1
Base Metrics AV:N/AC:H/Au:S/C:N/I:N/A:P
Access Vector Network
Access Complexity High
Authentication Single
Confidentiality Impact None
Integrity Impact None
Availability Impact Partial

Find out more about Red Hat support for the Common Vulnerability Scoring System (CVSS).

Red Hat Security Errata

Platform Errata Release Date
Red Hat Enterprise Linux 6 (sssd) RHSA-2015:2019 2015-11-10
Red Hat Enterprise Linux 7 (sssd) RHSA-2015:2355 2015-11-19

Affected Packages State

Platform Package State
Red Hat Satellite 6 sssd Will not fix
Red Hat Enterprise Linux 5 sssd Will not fix
Last Modified