Go to file
Lukas Slebodnik 4a8ad4c174 Resolves: rhbz#1499354 - CVE-2017-12173
sssd: unsanitized input when searching in local cache database access on
the sock_file system_bus_socket

(cherry picked from commit 7069858231)
2017-10-11 17:50:14 +02:00
.gitignore New upstream release 1.15.3 2017-07-25 13:58:52 +02:00
0001-Fix-minor-typos.patch Backport few upstream patches/fixes 2017-09-01 21:40:30 +02:00
0002-CACHE_REQ-Propagate-num_results-to-cache_req_state.patch Backport few upstream patches/fixes 2017-09-01 21:40:30 +02:00
0003-NSS-Move-shell-options-to-common-responder.patch Backport few upstream patches/fixes 2017-09-01 21:40:30 +02:00
0004-NSS-Move-nss_get_shell_override-to-responder-utils.patch Backport few upstream patches/fixes 2017-09-01 21:40:30 +02:00
0005-CONFIG-Add-session_recording-section.patch Backport few upstream patches/fixes 2017-09-01 21:40:30 +02:00
0006-BUILD-Support-configuring-session-recording-shell.patch Backport few upstream patches/fixes 2017-09-01 21:40:30 +02:00
0007-UTIL-Add-session-recording-conf-management-module.patch Backport few upstream patches/fixes 2017-09-01 21:40:30 +02:00
0008-RESPONDER-Add-session-recording-conf-loading.patch Backport few upstream patches/fixes 2017-09-01 21:40:30 +02:00
0009-DP-Add-session-recording-conf-loading.patch Backport few upstream patches/fixes 2017-09-01 21:40:30 +02:00
0010-SYSDB-Add-sessionRecording-attribute-macro.patch Backport few upstream patches/fixes 2017-09-01 21:40:30 +02:00
0011-DP-Load-override_space-into-be_ctx.patch Backport few upstream patches/fixes 2017-09-01 21:40:30 +02:00
0012-DP-Update-viewname-for-all-providers.patch Backport few upstream patches/fixes 2017-09-01 21:40:30 +02:00
0013-DP-Overlay-sessionRecording-attribute-on-initgr.patch Backport few upstream patches/fixes 2017-09-01 21:40:30 +02:00
0014-CACHE_REQ-Pull-sessionRecording-attrs-from-initgr.patch Backport few upstream patches/fixes 2017-09-01 21:40:30 +02:00
0015-NSS-Substitute-session-recording-shell.patch Backport few upstream patches/fixes 2017-09-01 21:40:30 +02:00
0016-PAM-Export-original-shell-to-tlog-rec-session.patch Backport few upstream patches/fixes 2017-09-01 21:40:30 +02:00
0017-INTG-Add-session-recording-tests.patch Backport few upstream patches/fixes 2017-09-01 21:40:30 +02:00
0018-MAN-Describe-session-recording-configuration.patch Backport few upstream patches/fixes 2017-09-01 21:40:30 +02:00
0019-SPEC-Use-language-file-for-sssd-kcm.patch Backport few upstream patches/fixes 2017-09-01 21:40:30 +02:00
0020-MAN-Don-t-tell-the-user-to-autostart-sssd-kcm.servic.patch Backport few upstream patches/fixes 2017-09-01 21:40:30 +02:00
0021-CACHE_REQ-Fix-warning-may-be-used-uninitialized.patch Backport few upstream patches/fixes 2017-09-01 21:40:30 +02:00
0022-INTG-Add-with-session-recording-bin-false-to-intgche.patch Backport few upstream patches/fixes 2017-09-01 21:40:30 +02:00
0023-Moving-headers-used-by-both-server-and-client-to-spe.patch Backport few upstream patches/fixes 2017-09-01 21:40:30 +02:00
0024-libwbclient-sssd-update-interface-to-version-0.14.patch Backport few upstream patches/fixes 2017-09-01 21:40:30 +02:00
0025-IFP-Do-not-fail-when-a-GHOST-group-is-not-found.patch Backport few upstream patches/fixes 2017-09-01 21:40:30 +02:00
0026-SHARED-Return-warning-back-about-minimal-header-file.patch Backport few upstream patches/fixes 2017-09-01 21:40:30 +02:00
0027-intg-Disable-add_remove-tests.patch Backport few upstream patches/fixes 2017-09-01 21:40:30 +02:00
0028-UTIL-Set-udp_preference_limit-0-in-krb5-snippet.patch Backport few upstream patches/fixes 2017-09-01 21:40:30 +02:00
0029-Fix-minor-typos.patch Backport few upstream patches/fixes 2017-09-01 21:40:30 +02:00
0030-Fix-minor-typos-in-docs.patch Backport few upstream patches/fixes 2017-09-01 21:40:30 +02:00
0031-SPEC-require-http-parser-only-on-rhel7.4.patch Backport few upstream patches/fixes 2017-09-01 21:40:30 +02:00
0032-intg-Increase-startup-timeouts-for-kcm-and-secrets.patch Backport few upstream patches/fixes 2017-09-01 21:40:30 +02:00
0033-sudo-add-a-threshold-option-to-reduce-size-of-rules-.patch Backport few upstream patches/fixes 2017-09-01 21:40:30 +02:00
0034-libwbclient-Change-return-code-for-wbcAuthenticateUs.patch Backport few upstream patches/fixes 2017-09-01 21:40:30 +02:00
0035-libwbclient-Fix-warning-statement-with-no-effect.patch Backport few upstream patches/fixes 2017-09-01 21:40:30 +02:00
0036-ldap_child-Removing-duplicate-log-message.patch Backport few upstream patches/fixes 2017-09-01 21:40:30 +02:00
0037-IFP-fix-typo-in-option-name-in-man-pages.patch Backport few upstream patches/fixes 2017-09-01 21:40:30 +02:00
0038-IFP-Filter-with-in-infopipe-group-methods.patch Backport few upstream patches/fixes 2017-09-01 21:40:30 +02:00
0039-IFP-Fix-of-limit-0-unlimited-result.patch Backport few upstream patches/fixes 2017-09-01 21:40:30 +02:00
0040-IFP-Change-ifp_list_ctx_remaining_capacity-return-ty.patch Backport few upstream patches/fixes 2017-09-01 21:40:30 +02:00
0041-IFP-Don-t-pre-allocate-the-amount-of-entries-request.patch Backport few upstream patches/fixes 2017-09-01 21:40:30 +02:00
0042-IPA_ACCESS-Remove-not-used-attribute.patch Backport few upstream patches/fixes 2017-09-01 21:40:30 +02:00
0043-IPA-Make-ipa_hbac_sysdb_save-more-generic.patch Backport few upstream patches/fixes 2017-09-01 21:40:30 +02:00
0044-IPA-Leave-only-HBAC-specific-defines-in-ipa_hbac_pri.patch Backport few upstream patches/fixes 2017-09-01 21:40:30 +02:00
0045-IPA_ACCESS-Make-hbac_get_cache_rules-more-generic.patch Backport few upstream patches/fixes 2017-09-01 21:40:30 +02:00
0046-IPA_ACCESS-Make-ipa_purge_hbac-more-generic.patch Backport few upstream patches/fixes 2017-09-01 21:40:30 +02:00
0047-IPA_RULES_COMMON-Introduce-ipa_common_save_rules.patch Backport few upstream patches/fixes 2017-09-01 21:40:30 +02:00
0048-IPA_RULES_COMMON-Introduce-ipa_common_get_hostgroupn.patch Backport few upstream patches/fixes 2017-09-01 21:40:30 +02:00
0049-IPA_ACCESS-Make-use-of-struct-ipa_common_entries.patch Backport few upstream patches/fixes 2017-09-01 21:40:30 +02:00
0050-IPA_COMMON-Introduce-ipa_get_host_attrs.patch Backport few upstream patches/fixes 2017-09-01 21:40:30 +02:00
0051-UTIL-move-files-selinux-.c-under-util-directory.patch Backport few upstream patches/fixes 2017-09-01 21:40:30 +02:00
0052-UTIL-Add-sss_create_dir.patch Backport few upstream patches/fixes 2017-09-01 21:40:30 +02:00
0053-DESKPROFILE-Introduce-the-new-IPA-session-provider.patch Backport few upstream patches/fixes 2017-09-01 21:40:30 +02:00
0054-HBAC-Fix-tevent-hierarchy-in-ipa_hbac_rule_info_send.patch Backport few upstream patches/fixes 2017-09-01 21:40:30 +02:00
0055-HBAC-Document-ipa_hbac_rule_info_next-s-behaviour.patch Backport few upstream patches/fixes 2017-09-01 21:40:30 +02:00
0056-HBAC-Remove-a-cosmetic-extra-space-from-an-if-clause.patch Backport few upstream patches/fixes 2017-09-01 21:40:30 +02:00
0057-HBAC-Improve-readability-of-ipa_hbac_rule_info_send.patch Backport few upstream patches/fixes 2017-09-01 21:40:30 +02:00
0058-HBAC-Enforce-coding-style-on-ipa_hbac_rule_info_send.patch Backport few upstream patches/fixes 2017-09-01 21:40:30 +02:00
0059-HBAC-Enforce-coding-style-ipa_hbac_rule_info_recv.patch Backport few upstream patches/fixes 2017-09-01 21:40:30 +02:00
0060-HBAC-Add-a-debug-message-in-case-ipa_hbac_rule_info_.patch Backport few upstream patches/fixes 2017-09-01 21:40:30 +02:00
0061-HBAC-Not-having-rules-should-not-be-logged-as-error.patch Backport few upstream patches/fixes 2017-09-01 21:40:30 +02:00
0062-DESKPROFILE-Add-ipa_deskprofile_request_interval.patch Backport few upstream patches/fixes 2017-09-01 21:40:30 +02:00
0063-NEGCACHE-Add-some-comments-about-each-step-of-sss_nc.patch Backport few upstream patches/fixes 2017-09-01 21:40:30 +02:00
0064-NEGCACHE-Always-add-root-to-the-negative-cache.patch Backport few upstream patches/fixes 2017-09-01 21:40:30 +02:00
0065-TEST_NEGCACHE-Test-that-root-is-always-added-to-ncac.patch Backport few upstream patches/fixes 2017-09-01 21:40:30 +02:00
0066-NEGCACHE-Descend-to-all-subdomains-when-adding-user-.patch Backport few upstream patches/fixes 2017-09-01 21:40:30 +02:00
0067-CACHE_REQ-Don-t-error-out-when-searching-by-id-0.patch Backport few upstream patches/fixes 2017-09-01 21:40:30 +02:00
0068-NSS-Don-t-error-out-when-deleting-an-entry-which-has.patch Backport few upstream patches/fixes 2017-09-01 21:40:30 +02:00
0069-NEGCACHE-Add-root-s-uid-gid-to-ncache.patch Backport few upstream patches/fixes 2017-09-01 21:40:30 +02:00
0070-TEST_NEGCACHE-Ensure-root-s-uid-and-gid-are-always-a.patch Backport few upstream patches/fixes 2017-09-01 21:40:30 +02:00
0071-TESTS-Add-wrappers-to-request-a-user-or-a-group-by-I.patch Backport few upstream patches/fixes 2017-09-01 21:40:30 +02:00
0072-TESTS-Add-files-provider-tests-that-request-a-user-a.patch Backport few upstream patches/fixes 2017-09-01 21:40:30 +02:00
0073-TESTS-Add-regression-tests-to-try-if-resolving-root-.patch Backport few upstream patches/fixes 2017-09-01 21:40:30 +02:00
0074-localauth-plugin-change-return-code-of-sss_an2ln.patch Backport few upstream patches/fixes 2017-09-01 21:40:30 +02:00
0075-tests-add-unit-tests-for-krb5-localauth-plugin.patch Backport few upstream patches/fixes 2017-09-01 21:40:30 +02:00
0076-CONFDB-Set-a-default-value-for-subdomain_refresh_int.patch Backport few upstream patches/fixes 2017-09-01 21:40:30 +02:00
0077-CONFDB-Do-not-crash-with-an-invalid-domain_type-or-c.patch Backport few upstream patches/fixes 2017-09-01 21:40:30 +02:00
0078-SDAP-Add-a-debug-message-to-explain-why-a-backend-wa.patch Backport few upstream patches/fixes 2017-09-01 21:40:30 +02:00
0079-SDAP-Don-t-call-be_mark_offline-because-sdap_id_conn.patch Backport few upstream patches/fixes 2017-09-01 21:40:30 +02:00
0080-PYTHON-Define-constants-as-bytes-instead-of-strings.patch Backport few upstream patches/fixes 2017-09-01 21:40:30 +02:00
0081-IPA-format-fixes.patch Backport few upstream patches/fixes 2017-09-01 21:40:30 +02:00
0082-SPEC-rhel8-will-have-python3-as-well.patch Backport few upstream patches/fixes 2017-09-01 21:40:30 +02:00
0083-SPEC-Fix-unowned-directory.patch Backport few upstream patches/fixes 2017-09-01 21:40:30 +02:00
0084-IPA-Only-attempt-migration-for-the-joined-domain.patch Backport few upstream patches/fixes 2017-09-01 21:40:30 +02:00
0085-SECRETS-Remove-unused-declarations.patch Backport few upstream patches/fixes 2017-09-01 21:40:30 +02:00
0086-SECRETS-Do-not-link-with-c-ares.patch Backport few upstream patches/fixes 2017-09-01 21:40:30 +02:00
0087-SECRETS-Store-quotas-in-a-per-hive-configuration-str.patch Backport few upstream patches/fixes 2017-09-01 21:40:30 +02:00
0088-SECRETS-Read-the-quotas-for-cn-secrets-from-secrets-.patch Backport few upstream patches/fixes 2017-09-01 21:40:30 +02:00
0089-SECRETS-Rename-local_db_req.basedn-to-local_db_req.r.patch Backport few upstream patches/fixes 2017-09-01 21:40:30 +02:00
0090-SECRETS-Use-separate-quotas-for-kcm-and-secrets-hive.patch Backport few upstream patches/fixes 2017-09-01 21:40:30 +02:00
0091-TESTS-Test-that-ccaches-can-be-stored-after-max_secr.patch Backport few upstream patches/fixes 2017-09-01 21:40:30 +02:00
0092-SECRETS-Add-a-new-option-to-control-per-UID-limits.patch Backport few upstream patches/fixes 2017-09-01 21:40:30 +02:00
0093-SECRETS-Support-0-as-unlimited-for-the-quotas.patch Backport few upstream patches/fixes 2017-09-01 21:40:30 +02:00
0094-TESTS-Relax-the-assert-in-test_idle_timeout.patch Fix few bugs/regressions 2017-09-12 09:28:42 +02:00
0095-IPA-Reword-the-DEBUG-message-about-SRV-resolution-on.patch Fix few bugs/regressions 2017-09-12 09:28:42 +02:00
0097-SYSDB-Add-sysdb_search_by_orig_dn.patch Fix few bugs/regressions 2017-09-12 09:28:42 +02:00
0098-TESTS-Add-tests-for-sysdb_search_-users-groups-_by_o.patch Fix few bugs/regressions 2017-09-12 09:28:42 +02:00
0099-IPA-Use-sysdb_search_-_by_orig_dn-_hbac_users.c.patch Fix few bugs/regressions 2017-09-12 09:28:42 +02:00
0100-SDAP-Use-sysdb_search_-_by_orig_dn-in-sdap_async_nes.patch Fix few bugs/regressions 2017-09-12 09:28:42 +02:00
0101-SDAP-Use-sysdb_search_-_by_orig_dn-in-sdap_async_gro.patch Fix few bugs/regressions 2017-09-12 09:28:42 +02:00
0102-IPA-Use-sysdb_search_-_by_orig_dn-in-_subdomains_ext.patch Fix few bugs/regressions 2017-09-12 09:28:42 +02:00
0103-MAN-Improve-description-of-trusted-domain-section-in.patch Fix few bugs/regressions 2017-09-12 09:28:42 +02:00
0104-certmap-add-OpenSSL-implementation.patch Fix few bugs/regressions 2017-09-12 09:28:42 +02:00
0105-MAN-Improve-failover-documentation-by-explaining-the.patch Fix few bugs/regressions 2017-09-12 09:28:42 +02:00
0106-MAN-Document-that-the-secrets-provider-can-only-be-s.patch Fix few bugs/regressions 2017-09-12 09:28:42 +02:00
0107-SELINUX-Use-getseuserbyname-to-get-IPA-seuser.patch Fix few bugs/regressions 2017-09-12 09:28:42 +02:00
0108-certmap-Suppress-warning-Wmissing-braces.patch Fix few bugs/regressions 2017-09-12 09:28:42 +02:00
0109-cache_req-Look-for-name-attribute-also-in-nss_cmd_ge.patch Fix few bugs/regressions 2017-09-12 09:28:42 +02:00
0110-ipa-make-sure-view-name-is-initialized-at-startup.patch Fix few bugs/regressions 2017-09-12 09:28:42 +02:00
0111-DP-Add-Generic-DP-Request-Probes.patch Fix few bugs/regressions 2017-09-12 09:28:42 +02:00
0112-CONTRIB-Add-DP-Request-analysis-script.patch Fix few bugs/regressions 2017-09-12 09:28:42 +02:00
0113-MAN-Add-sssd-systemtap-man-page.patch Fix few bugs/regressions 2017-09-12 09:28:42 +02:00
0114-TESTS-Use-NULL-for-pointer-not-0.patch Fix few bugs/regressions 2017-09-12 09:28:42 +02:00
0115-SUDO-Use-initgr_with_views-when-looking-up-a-sudo-us.patch Fix few bugs/regressions 2017-09-12 09:28:42 +02:00
0116-sysdb-sanitize-search-filter-input.patch Resolves: rhbz#1499354 - CVE-2017-12173 2017-10-11 17:50:14 +02:00
0502-SYSTEMD-Use-capabilities.patch New upstream release 1.15.0 2017-01-27 20:07:00 +01:00
sources New upstream release 1.15.3 2017-07-25 13:58:52 +02:00
sssd.spec Resolves: rhbz#1499354 - CVE-2017-12173 2017-10-11 17:50:14 +02:00