PT-2014-4793 · Linux+3 · Linux-Pam+3

Sebastian Krahmer

·

Published

2014-04-10

·

Updated

2024-06-15

·

CVE-2014-2583

CVSS v2.0

5.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Linux-PAM version 1.1.8
Description The issue concerns multiple directory traversal vulnerabilities in the pam timestamp module. These vulnerabilities allow local users to create arbitrary files or possibly bypass authentication. This can be achieved by including a .. (dot dot) in the PAM RUSER value to the get ruser function or the PAM TTY value to the check tty function, which is used by the format timestamp name function.
Recommendations For Linux-PAM version 1.1.8, consider restricting the use of the pam timestamp module until a patch is available. As a temporary workaround, restrict access to the get ruser and check tty functions to minimize the risk of exploitation. Avoid using the PAM RUSER and PAM TTY values in sensitive operations until the issue is resolved.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2016-1613
CVE-2014-2583
MGASA-2015-0213
OPENSUSE-SU-2024:10405-1
SUSE-SU-2014_0631-1
USN-2935-1
USN-2935-2

Affected Products

Alt Linux
Linux-Pam
Suse
Ubuntu