PT-2007-1386 · Util Linux+1 · Util-Linux+1
Craig Lawson
·
Published
2007-03-04
·
Updated
2017-10-11
·
CVE-2006-7108
CVSS v2.0
4.1
Medium
| Vector | AV:L/AC:M/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
util-linux version 2.12a
Description
The issue allows users to bypass intended access policies that would be enforced by
pam acct mgmt and chauth tok when authentication is skipped, such as in a Kerberos krlogin session. This might enable users to circumvent access controls.Recommendations
For util-linux version 2.12a, consider updating to a newer version that addresses this issue, as the current version may allow users to bypass access policies. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Red Hat
Util-Linux