CVE-2024-47191

pam_oath.so in oath-toolkit 2.6.7 through 2.6.11 before 2.6.12 allows root privilege escalation because, in the context of PAM code running as root, it mishandles usersfile access, such as by calling fchown in the presence of a symlink.
Configurations

No configuration.

History

21 Nov 2024, 09:39

Type Values Removed Values Added
References
  • () http://www.openwall.com/lists/oss-security/2024/10/04/2 -
  • () http://www.openwall.com/lists/oss-security/2024/10/05/1 -
  • () http://www.openwall.com/lists/oss-security/2024/10/08/1 -
  • () http://www.openwall.com/lists/oss-security/2024/10/08/2 -
  • () http://www.openwall.com/lists/oss-security/2024/10/08/4 -
  • () http://www.openwall.com/lists/oss-security/2024/10/15/7 -
  • () http://www.openwall.com/lists/oss-security/2024/10/17/1 -
  • () http://www.openwall.com/lists/oss-security/2024/10/18/1 -
  • () http://www.openwall.com/lists/oss-security/2024/10/18/2 -

09 Oct 2024, 21:35

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.1
CWE CWE-22
Summary
  • (es) pam_oath.so en oath-toolkit 2.6.7 a 2.6.11 antes de 2.6.12 permite la escalada de privilegios de root porque, en el contexto del código PAM que se ejecuta como root, maneja incorrectamente el acceso a los archivos de los usuarios, como al llamar a fchown en presencia de un enlace simbólico.

09 Oct 2024, 05:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-10-09 05:15

Updated : 2024-11-21 09:39


NVD link : CVE-2024-47191

Mitre link : CVE-2024-47191

CVE.ORG link : CVE-2024-47191


JSON object : View

Products Affected

No product.

CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')