PT-2014-4793 · Linux+3 · Linux-Pam+3

Sebastian Krahmer

·

Publicado

2014-04-10

·

Atualizado

2024-06-15

·

CVE-2014-2583

CVSS v2.0

5.8

Média

VetorAV:N/AC:M/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Linux-PAM version 1.1.8
Description The issue concerns multiple directory traversal vulnerabilities in the pam timestamp module. These vulnerabilities allow local users to create arbitrary files or possibly bypass authentication. This can be achieved by including a .. (dot dot) in the PAM RUSER value to the get ruser function or the PAM TTY value to the check tty function, which is used by the format timestamp name function.
Recommendations For Linux-PAM version 1.1.8, consider restricting the use of the pam timestamp module until a patch is available. As a temporary workaround, restrict access to the get ruser and check tty functions to minimize the risk of exploitation. Avoid using the PAM RUSER and PAM TTY values in sensitive operations until the issue is resolved.

Exploit

Correção

Path traversal

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2016-1613
CVE-2014-2583
MGASA-2015-0213
OPENSUSE-SU-2024:10405-1
SUSE-SU-2014_0631-1
USN-2935-1
USN-2935-2

Produtos afetados

Alt Linux
Linux-Pam
Suse
Ubuntu