CVE-2024-37408

fprintd through 1.94.3 lacks a security attention mechanism, and thus unexpected actions might be authorized by "auth sufficient pam_fprintd.so" for Sudo. NOTE: the supplier disputes this because they believe issue resolution would involve modifying the PAM configuration to restrict pam_fprintd.so to front-ends that implement a proper attention mechanism, not modifying pam_fprintd.so or fprintd.
Configurations

No configuration.

History

06 Sep 2024, 19:35

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.3
CWE CWE-287

14 Jun 2024, 21:15

Type Values Removed Values Added
References
  • () http://www.openwall.com/lists/oss-security/2024/06/14/3 -

14 Jun 2024, 16:15

Type Values Removed Values Added
References
  • () http://www.openwall.com/lists/oss-security/2024/06/14/2 -

14 Jun 2024, 15:15

Type Values Removed Values Added
References
  • () http://www.openwall.com/lists/oss-security/2024/06/14/1 -

13 Jun 2024, 22:15

Type Values Removed Values Added
References
  • () http://www.openwall.com/lists/oss-security/2024/06/13/3 -
  • () https://www.openwall.com/lists/oss-security/2024/06/13/2 -
Summary
  • (es) fprintd hasta 1.94.3 carece de un mecanismo de atención de seguridad y, por lo tanto, es posible que se autoricen acciones inesperadas mediante "auth suficiente pam_fprintd.so" para Sudo.
Summary (en) fprintd through 1.94.3 lacks a security attention mechanism, and thus unexpected actions might be authorized by "auth sufficient pam_fprintd.so" for Sudo. (en) fprintd through 1.94.3 lacks a security attention mechanism, and thus unexpected actions might be authorized by "auth sufficient pam_fprintd.so" for Sudo. NOTE: the supplier disputes this because they believe issue resolution would involve modifying the PAM configuration to restrict pam_fprintd.so to front-ends that implement a proper attention mechanism, not modifying pam_fprintd.so or fprintd.

08 Jun 2024, 14:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-06-08 14:15

Updated : 2024-09-06 19:35


NVD link : CVE-2024-37408

Mitre link : CVE-2024-37408

CVE.ORG link : CVE-2024-37408


JSON object : View

Products Affected

No product.

CWE
CWE-287

Improper Authentication