CVE-2010-4341 describes a denial-of-service vulnerability in the pam_parse_in_data_v2 function within the PAM responder of SSSD versions 1.5.0, 1.4.x, and 1.3, affecting Fedora Hosted SSSD and Fedora Project SSSD. A local attacker can exploit this flaw by sending a specially crafted packet, leading to an infinite loop, system crash, and prevention of logins. The vulnerability has a low CVSS score (2.1) with a vector of AV:L/AC:L/Au:N/C:N/I:N/A:P, indicating local access, low attack complexity, no authentication required, and only availability impact. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.4.0CPE matchmatch criteria | cpe:2.3:a:fedorahosted:sssd:1.4.0:*:*:*:*:*:*:* | ||
1.4.1CPE matchmatch criteria | cpe:2.3:a:fedorahosted:sssd:1.4.1:*:*:*:*:*:*:* | ||
1.3.0CPE matchmatch criteria | cpe:2.3:a:fedoraproject:sssd:1.3.0:*:*:*:*:*:*:* | ||
1.5.0CPE matchmatch criteria | cpe:2.3:a:fedoraproject:sssd:1.5.0:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:L/Au:N/C:N/I:N/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.6 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.