cve/2015/CVE-2015-5292.md
2024-06-18 02:51:15 +02:00

867 B

CVE-2015-5292

Description

Memory leak in the Privilege Attribute Certificate (PAC) responder plugin (sssd_pac_plugin.so) in System Security Services Daemon (SSSD) 1.10 before 1.13.1 allows remote authenticated users to cause a denial of service (memory consumption) via a large number of logins that trigger parsing of PAC blobs during Kerberos authentication.

POC

Reference

Github