CVE-2024-47191

Publication date

2024-10-09 00:00:00

Family

mitre

State

PUBLISHED

Description

pam_oath.so in oath-toolkit 2.6.7 through 2.6.11 before 2.6.12 allows root privilege escalation because, in the context of PAM code running as root, it mishandles usersfile access, such as by calling fchown in the presence of a symlink.