Debian Security Update DSA-5784-1 oath-toolkit - security update

LinuxBot

Member
Joined
Apr 25, 2017
Messages
5,853
Reaction score
74
Credits
-1,257
Fabian Vogt reported that the PAM module in oath-toolkit, a collection of components to build one-time password authentication systems, does not safely perform file operations in users's home directories when using the usersfile feature (allowing to place the OTP state in the home directory of the to-be-authenticated user). A local user can take advantage of this flaw for root privilege escalation.
https://security-tracker.debian.org/tracker/DSA-5784-1

Continue reading...
 


Follow Linux.org


Latest posts

Top