Risk | Medium |
Patch available | YES |
Number of vulnerabilities | 1 |
CVE-ID | CVE-2023-3758 |
CWE-ID | CWE-362 |
Exploitation vector | Network |
Public exploit | N/A |
Vulnerable software |
SUSE Linux Enterprise Micro for Rancher Operating systems & Components / Operating system SUSE Linux Enterprise Server for SAP Applications 15 Operating systems & Components / Operating system SUSE Linux Enterprise Server 15 SP3 LTSS Operating systems & Components / Operating system SUSE Linux Enterprise Server 15 Operating systems & Components / Operating system SUSE Linux Enterprise High Performance Computing LTSS 15 Operating systems & Components / Operating system SUSE Linux Enterprise High Performance Computing 15 Operating systems & Components / Operating system SUSE Enterprise Storage Operating systems & Components / Operating system SUSE Linux Enterprise Micro Operating systems & Components / Operating system openSUSE Leap Operating systems & Components / Operating system sssd-common-64bit Operating systems & Components / Operating system package or component sssd-common-64bit-debuginfo Operating systems & Components / Operating system package or component sssd-common-32bit-debuginfo Operating systems & Components / Operating system package or component sssd-common-32bit Operating systems & Components / Operating system package or component libsss_simpleifp0 Operating systems & Components / Operating system package or component sssd-tools Operating systems & Components / Operating system package or component sssd-ldap Operating systems & Components / Operating system package or component sssd-wbclient-debuginfo Operating systems & Components / Operating system package or component sssd-common Operating systems & Components / Operating system package or component libnfsidmap-sss-debuginfo Operating systems & Components / Operating system package or component sssd-ipa-debuginfo Operating systems & Components / Operating system package or component libsss_nss_idmap-devel Operating systems & Components / Operating system package or component sssd-debugsource Operating systems & Components / Operating system package or component sssd-common-debuginfo Operating systems & Components / Operating system package or component python3-ipa_hbac Operating systems & Components / Operating system package or component sssd-ldap-debuginfo Operating systems & Components / Operating system package or component sssd-krb5 Operating systems & Components / Operating system package or component python3-ipa_hbac-debuginfo Operating systems & Components / Operating system package or component libipa_hbac-devel Operating systems & Components / Operating system package or component libsss_idmap0-debuginfo Operating systems & Components / Operating system package or component sssd Operating systems & Components / Operating system package or component python3-sss-murmur-debuginfo Operating systems & Components / Operating system package or component python3-sssd-config-debuginfo Operating systems & Components / Operating system package or component sssd-tools-debuginfo Operating systems & Components / Operating system package or component sssd-proxy-debuginfo Operating systems & Components / Operating system package or component libsss_idmap-devel Operating systems & Components / Operating system package or component libsss_idmap0 Operating systems & Components / Operating system package or component libsss_nss_idmap0 Operating systems & Components / Operating system package or component sssd-proxy Operating systems & Components / Operating system package or component sssd-ad Operating systems & Components / Operating system package or component libnfsidmap-sss Operating systems & Components / Operating system package or component libsss_simpleifp-devel Operating systems & Components / Operating system package or component libsss_simpleifp0-debuginfo Operating systems & Components / Operating system package or component sssd-ipa Operating systems & Components / Operating system package or component sssd-winbind-idmap-debuginfo Operating systems & Components / Operating system package or component libsss_certmap0 Operating systems & Components / Operating system package or component libipa_hbac0-debuginfo Operating systems & Components / Operating system package or component sssd-krb5-debuginfo Operating systems & Components / Operating system package or component libipa_hbac0 Operating systems & Components / Operating system package or component python3-sss_nss_idmap-debuginfo Operating systems & Components / Operating system package or component sssd-winbind-idmap Operating systems & Components / Operating system package or component sssd-wbclient-devel Operating systems & Components / Operating system package or component sssd-dbus-debuginfo Operating systems & Components / Operating system package or component sssd-krb5-common-debuginfo Operating systems & Components / Operating system package or component sssd-dbus Operating systems & Components / Operating system package or component libsss_certmap0-debuginfo Operating systems & Components / Operating system package or component python3-sss-murmur Operating systems & Components / Operating system package or component libsss_certmap-devel Operating systems & Components / Operating system package or component python3-sssd-config Operating systems & Components / Operating system package or component sssd-ad-debuginfo Operating systems & Components / Operating system package or component libsss_nss_idmap0-debuginfo Operating systems & Components / Operating system package or component sssd-wbclient Operating systems & Components / Operating system package or component sssd-krb5-common Operating systems & Components / Operating system package or component python3-sss_nss_idmap Operating systems & Components / Operating system package or component |
Vendor | SUSE |
Security Bulletin
This security bulletin contains one medium risk vulnerability.
EUVDB-ID: #VU88857
Risk: Medium
CVSSv4.0: 1.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:U/U:Green]
CVE-ID: CVE-2023-3758
Exploit availability: No
DescriptionThe vulnerability allows a remote user to escalate privileges on the system.
The vulnerability exists due to a race condition where the GPO policy is not consistently applied for authenticated users. A remote user can exploit the race and gain unauthorized access to the system.
MitigationUpdate the affected package sssd to the latest version.
Vulnerable software versionsSUSE Linux Enterprise Micro for Rancher: 5.2
SUSE Linux Enterprise Server for SAP Applications 15: SP3
SUSE Linux Enterprise Server 15 SP3 LTSS: 15-SP3
SUSE Linux Enterprise Server 15: SP3
SUSE Linux Enterprise High Performance Computing LTSS 15: SP3
SUSE Linux Enterprise High Performance Computing 15: SP3
SUSE Enterprise Storage: 7.1
SUSE Linux Enterprise Micro: 5.1 - 5.2
openSUSE Leap: 15.3
sssd-common-64bit: before 1.16.1-150300.23.43.1
sssd-common-64bit-debuginfo: before 1.16.1-150300.23.43.1
sssd-common-32bit-debuginfo: before 1.16.1-150300.23.43.1
sssd-common-32bit: before 1.16.1-150300.23.43.1
libsss_simpleifp0: before 1.16.1-150300.23.43.1
sssd-tools: before 1.16.1-150300.23.43.1
sssd-ldap: before 1.16.1-150300.23.43.1
sssd-wbclient-debuginfo: before 1.16.1-150300.23.43.1
sssd-common: before 1.16.1-150300.23.43.1
libnfsidmap-sss-debuginfo: before 1.16.1-150300.23.43.1
sssd-ipa-debuginfo: before 1.16.1-150300.23.43.1
libsss_nss_idmap-devel: before 1.16.1-150300.23.43.1
sssd-debugsource: before 1.16.1-150300.23.43.1
sssd-common-debuginfo: before 1.16.1-150300.23.43.1
python3-ipa_hbac: before 1.16.1-150300.23.43.1
sssd-ldap-debuginfo: before 1.16.1-150300.23.43.1
sssd-krb5: before 1.16.1-150300.23.43.1
python3-ipa_hbac-debuginfo: before 1.16.1-150300.23.43.1
libipa_hbac-devel: before 1.16.1-150300.23.43.1
libsss_idmap0-debuginfo: before 1.16.1-150300.23.43.1
sssd: before 1.16.1-150300.23.43.1
python3-sss-murmur-debuginfo: before 1.16.1-150300.23.43.1
python3-sssd-config-debuginfo: before 1.16.1-150300.23.43.1
sssd-tools-debuginfo: before 1.16.1-150300.23.43.1
sssd-proxy-debuginfo: before 1.16.1-150300.23.43.1
libsss_idmap-devel: before 1.16.1-150300.23.43.1
libsss_idmap0: before 1.16.1-150300.23.43.1
libsss_nss_idmap0: before 1.16.1-150300.23.43.1
sssd-proxy: before 1.16.1-150300.23.43.1
sssd-ad: before 1.16.1-150300.23.43.1
libnfsidmap-sss: before 1.16.1-150300.23.43.1
libsss_simpleifp-devel: before 1.16.1-150300.23.43.1
libsss_simpleifp0-debuginfo: before 1.16.1-150300.23.43.1
sssd-ipa: before 1.16.1-150300.23.43.1
sssd-winbind-idmap-debuginfo: before 1.16.1-150300.23.43.1
libsss_certmap0: before 1.16.1-150300.23.43.1
libipa_hbac0-debuginfo: before 1.16.1-150300.23.43.1
sssd-krb5-debuginfo: before 1.16.1-150300.23.43.1
libipa_hbac0: before 1.16.1-150300.23.43.1
python3-sss_nss_idmap-debuginfo: before 1.16.1-150300.23.43.1
sssd-winbind-idmap: before 1.16.1-150300.23.43.1
sssd-wbclient-devel: before 1.16.1-150300.23.43.1
sssd-dbus-debuginfo: before 1.16.1-150300.23.43.1
sssd-krb5-common-debuginfo: before 1.16.1-150300.23.43.1
sssd-dbus: before 1.16.1-150300.23.43.1
libsss_certmap0-debuginfo: before 1.16.1-150300.23.43.1
python3-sss-murmur: before 1.16.1-150300.23.43.1
libsss_certmap-devel: before 1.16.1-150300.23.43.1
python3-sssd-config: before 1.16.1-150300.23.43.1
sssd-ad-debuginfo: before 1.16.1-150300.23.43.1
libsss_nss_idmap0-debuginfo: before 1.16.1-150300.23.43.1
sssd-wbclient: before 1.16.1-150300.23.43.1
sssd-krb5-common: before 1.16.1-150300.23.43.1
python3-sss_nss_idmap: before 1.16.1-150300.23.43.1
CPE2.3https://www.suse.com/support/update/announcement/2024/suse-su-20241549-1/
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote authenticated user via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.