Local root vulnerability in pam-python

In the provided project pam-python PAM module that allows connecting authentication modules in Python, identified vulnerability (CVE-2019-16729), which enables privilege escalation in the system. When using the vulnerable version of pam-python (which is not installed by default), a local user can gain access with root privileges through manipulations with the default environment variables processed in Python (for example, it is possible to initiate the saving of a file with bytecode to overwrite system files).

The vulnerability exists in the latest stable release 1.0.6, which has been available since August 2016. The issue was identified during an audit of the pam-python PAM module conducted by the team openSUSE Security Team, and has already been fixed in the update 1.0.7. The status of updates for the pam-python package can be tracked on the following pages: Debian, Ubuntu, Arch. In Fedora and RHEL, the module is not provided.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster