PT-2022-7849 · Unknown · Pam Tacplus

Published

2022-04-21

·

Updated

2022-05-02

·

CVE-2016-20014

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions pam tacplus versions prior to 1.4.1
Description The issue arises from the pam sm acct mgmt function in pam tacplus.c not properly zeroing out the arep data structure. This could potentially lead to sensitive information disclosure.
Recommendations For versions prior to 1.4.1, update to version 1.4.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the pam sm acct mgmt function until a patch is available.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2016-20014

Affected Products

Pam Tacplus