PT-2014-3364 · Oath · Oath Toolkit

Bas Van Schaik

·

Published

2014-02-25

·

Updated

2024-06-15

·

CVE-2013-7322

CVSS v2.0

4.9

Medium

VectorAV:N/AC:M/Au:S/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions OATH Toolkit versions prior to 2.4.1
Description The issue arises from the improper handling of lines containing an invalid one-time-password (OTP) type and a user name in /etc/users.oath by the usersfile.c in liboath. This leads to the wrong line being updated when invalidating an OTP, allowing context-dependent attackers to conduct replay attacks. For instance, this can be demonstrated by a commented out line when using libpam-oath.
Recommendations For OATH Toolkit versions prior to 2.4.1, update to version 2.4.1 or later to resolve the issue.

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2013-7322
MGASA-2014-0101
OPENSUSE-SU-2024:11104-1

Affected Products

Oath Toolkit