PT-2020-13746 · Unknown+2 · Pam Tacplus+2

The-Magician

·

Published

2020-06-06

·

Updated

2022-04-05

·

CVE-2020-13881

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions pam tacplus versions 1.3.8 through 1.5.1
Description The issue concerns the logging of the TACACS+ shared secret via syslog when the DEBUG loglevel and journald are used. This occurs in the support.c file of pam tacplus.
Recommendations For pam tacplus versions 1.3.8 through 1.5.1, consider disabling the DEBUG loglevel or journald to prevent the TACACS+ shared secret from being logged via syslog until a patch is available.

Fix

Insertion into Log File

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-13881
DLA-2239-1
DLA-2730-1
USN-4521-1

Affected Products

Linuxmint
Ubuntu
Pam Tacplus