CVE-2014-0249: Fedoraproject Sssd
Low severity, CVSS 3.3. EPSS: 0.3% chance of exploitation in the next 30 days.
The System Security Services Daemon (SSSD) 1.11.6 does not properly identify group membership when a non-POSIX group is in a group membership chain, which allows local users to bypass access restrictions via unspecified vectors.
Affected products
- Fedoraproject Sssd: version 1.11.6 only
- Red Hat Enterprise Linux: version 5 only; version 6.0 only
Published 2014-06-11. Last modified 2026-06-17.