CVE-2015-5292

EPSS 2.7%
Published: 10/29/2015Modified: 5/10/2026
Also known as:DEBIAN-CVE-2015-5292

Description

Memory leak in the Privilege Attribute Certificate (PAC) responder plugin (sssd_pac_plugin.so) in System Security Services Daemon (SSSD) 1.10 before 1.13.1 allows remote authenticated users to cause a denial of service (memory consumption) via a large number of logins that trigger parsing of PAC blobs during Kerberos authentication.

Affected packages (1)

References (1)