CVE-2019-3811

Source
https://cve.org/CVERecord?id=CVE-2019-3811
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-3811.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2019-3811
Downstream
Related
Published
2019-01-15T15:29:00.360Z
Modified
2026-04-02T03:10:29.023159Z
Severity
  • 5.2 (Medium) CVSS_V3 - CVSS:3.1/AV:A/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H CVSS Calculator
Summary
[none]
Details

A vulnerability was found in sssd. If a user was configured with no home directory set, sssd would return '/' (the root directory) instead of '' (the empty string / no home directory). This could impact services that restrict the user's filesystem access to within their home directory through chroot() etc. All versions before 2.1 are vulnerable.

References

Affected packages

Git / github.com/sssd/sssd

Affected ranges

Type
GIT
Repo
https://github.com/sssd/sssd
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
{
    "versions": [
        {
            "introduced": "0"
        },
        {
            "fixed": "2.1"
        }
    ]
}

Affected versions

Other
sssd-0_2_0
sssd-0_2_1
sssd-0_3_0
sssd-0_3_1
sssd-0_3_2
sssd-0_3_3
sssd-0_4_0
sssd-0_4_1
sssd-0_5_0
sssd-0_6_0
sssd-0_6_1
sssd-0_7_0
sssd-0_7_1
sssd-0_99_0
sssd-0_99_1
sssd-1_0_0
sssd-1_0_1
sssd-1_0_2
sssd-1_0_3
sssd-1_0_4
sssd-1_0_5
sssd-1_0_6
sssd-1_0_7
sssd-1_0_7-2
sssd-1_0_8
sssd-1_0_99
sssd-1_10_0
sssd-1_10_1
sssd-1_10_90
sssd-1_10_92
sssd-1_10_alpha1
sssd-1_10_beta1
sssd-1_10_beta2
sssd-1_11_0
sssd-1_11_0_beta1
sssd-1_11_0_beta2
sssd-1_11_1
sssd-1_11_2
sssd-1_11_3
sssd-1_11_4
sssd-1_11_5
sssd-1_11_5_1
sssd-1_11_6
sssd-1_11_7
sssd-1_11_8
sssd-1_11_90
sssd-1_11_91
sssd-1_12_0
sssd-1_12_0_beta1
sssd-1_12_0_beta2
sssd-1_12_1
sssd-1_12_2
sssd-1_12_3
sssd-1_12_4
sssd-1_12_5
sssd-1_12_90
sssd-1_13_0
sssd-1_13_0_alpha
sssd-1_13_1
sssd-1_13_2
sssd-1_13_3
sssd-1_13_4
sssd-1_13_90
sssd-1_13_91
sssd-1_14_0
sssd-1_14_0_alpha1
sssd-1_14_0_beta1
sssd-1_14_1
sssd-1_14_2
sssd-1_15_0
sssd-1_15_1
sssd-1_15_2
sssd-1_15_3
sssd-1_16_0
sssd-1_16_1
sssd-1_16_2
sssd-1_16_3
sssd-1_16_4
sssd-1_16_5
sssd-1_1_0
sssd-1_1_1
sssd-1_1_2
sssd-1_1_91
sssd-1_1_92
sssd-1_2_0
sssd-1_2_1
sssd-1_2_2
sssd-1_2_3
sssd-1_2_4
sssd-1_2_91
sssd-1_3_0
sssd-1_3_1
sssd-1_4_0
sssd-1_4_1
sssd-1_5_0
sssd-1_5_1
sssd-1_5_10
sssd-1_5_11
sssd-1_5_12
sssd-1_5_13
sssd-1_5_14
sssd-1_5_15
sssd-1_5_16
sssd-1_5_17
sssd-1_5_2
sssd-1_5_3
sssd-1_5_4
sssd-1_5_5
sssd-1_5_6
sssd-1_5_6_1
sssd-1_5_7
sssd-1_5_8
sssd-1_5_9
sssd-1_6_0
sssd-1_6_1
sssd-1_6_2
sssd-1_6_3
sssd-1_6_4
sssd-1_7_0
sssd-1_7_91
sssd-1_7_92
sssd-1_7_93
sssd-1_8_0
sssd-1_8_0_beta1
sssd-1_8_0_beta2
sssd-1_8_0_beta3
sssd-1_8_1
sssd-1_8_2
sssd-1_8_3
sssd-1_8_4
sssd-1_8_5
sssd-1_8_6
sssd-1_8_91
sssd-1_8_92
sssd-1_8_93
sssd-1_8_94
sssd-1_8_95
sssd-1_8_96
sssd-1_8_97
sssd-1_8_98
sssd-1_9_0
sssd-1_9_0_beta1
sssd-1_9_0_beta2
sssd-1_9_0_beta3
sssd-1_9_0_beta4
sssd-1_9_0_beta5
sssd-1_9_0_beta6
sssd-1_9_0_beta7
sssd-1_9_0_rc1
sssd-1_9_1
sssd-1_9_2
sssd-1_9_3
sssd-1_9_4
sssd-1_9_5
sssd-1_9_6
sssd-1_9_7
sssd-1_9_91
sssd-1_9_92
sssd-1_9_93
sssd-1_9_94
sssd-2_0_0

Database specific

unresolved_ranges
[
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "last_affected": "8.0"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "last_affected": "15.0"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "last_affected": "42.3"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "last_affected": "7.0"
            }
        ]
    }
]
source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-3811.json"