Fedorahosted hosts a modest portfolio of infrastructure and system-management components, including the cronie job scheduler, SSSD identity-service daemon, and Newt user-interface library, each of which can occupy sensitive roles in authentication and task automation. Observed vulnerabilities across this portfolio cluster around sensitive-information disclosure, improper authentication handling, insecure file-access patterns including link-following issues, and memory-buffer boundary violations—weakness classes typical of lower-level system software where access control and input parsing are critical. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Fedorahosted over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2009-2410HIGH The local_handler_callback function in server/responder/pam/pam_LOCAL_domain.c in sssd 0.4.1 does not properly handle blank-password accounts in the SSSD BE database, which allows | Jul 30, 2009 | 7.5 | 20 | NO | NO |
CVE-2009-2905MEDIUM Heap-based buffer overflow in textbox.c in newt 0.51.5, 0.51.6, and 0.52.2 allows local users to cause a denial of service (application crash) or possibly execute arbitrary code vi | Sep 29, 2009 | 4.6 | 19 | NO | NO |
CVE-2012-6097MEDIUM File descriptor leak in cronie 1.4.8, when running in certain environments, might allow local users to read restricted files, as demonstrated by reading /etc/crontab. | Apr 9, 2013 | 4.3 | 18 | NO | NO |
The edit_cmd function in crontab.c in (1) cronie before 1.4.4 and (2) Vixie cron (vixie-cron) allows local users to change the modification times of arbitrary files, and consequent | Feb 25, 2010 | 3.3 | 17 | NO | NO |
The pam_parse_in_data_v2 function in src/responder/pam/pamsrv_cmd.c in the PAM responder in SSSD 1.5.0, 1.4.x, and 1.3 allows local users to cause a denial of service (infinite loo | Jan 25, 2011 | 2.1 | 13 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Fedorahosted.
Media articles that mention a CVE ID that affects a product developed by Fedorahosted — matched by CVE ID, not by vendor name.