Beveiligingsadvies

CVE-2024-47191

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2024-10-09 00:00:00
Laatst bijgewerkt 2024-10-18 03:08:08
Toegewezen door mitre
CVSS-score 7.1
Status PUBLISHED

Beschrijving

pam_oath.so in oath-toolkit 2.6.7 through 2.6.11 before 2.6.12 allows root privilege escalation because, in the context of PAM code running as root, it mishandles usersfile access, such as by calling fchown in the presence of a symlink.