PT-2018-14297 · Suse+1 · Opensuse Leap+3
Daniel Pecka
·
Publicado
2018-11-27
·
Atualizado
2024-06-15
·
CVE-2018-17953
CVSS v2.0
9.3
Alta
| Vetor | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
openSUSE Leap version 15.0
SUSE Linux Enterprise version 15
Description
The issue is related to an incorrect variable in a SUSE specific patch for pam access rule matching in PAM, which could lead to pam access rules not being applied, resulting in a fail open scenario.
Recommendations
For openSUSE Leap version 15.0, update the PAM package to a version that includes the corrected patch.
For SUSE Linux Enterprise version 15, apply the appropriate patch or update to ensure pam access rules are correctly applied.
Correção
Improper Access Control
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Pam
Suse Linux Enterprise
Suse
Opensuse Leap