Local root vulnerability in pam-python

In the provided by the project pam-python PAM module that allows you to connect authentication modules in the Python language, identified vulnerability (CVE-2019-16729), which gives you the opportunity to increase your privileges in the system. When using a vulnerable version of pam-python (not installed by default), a local user can gain root access by manipulation with environment variables handled by Python by default (for example, you can trigger saving a file with bytecode to overwrite system files).

The vulnerability is present in the latest stable release 1.0.6, offered since August 2016. The issue was identified during an audit of the pam-python PAM module conducted by the developers from the team openSUSE Security Team, and already fixed in the update 1.0.7. The status of updates to pam-python packages can be tracked on the following pages: Debian, Ubuntu, SUSE/openSUSE. Fedora and RHEL module not supplied.

Source: opennet.ru

Add a comment