PAM module may allow accessing with the credentials of another user
Hallo zusammen, sofern nicht selber schon gesehen/-lesen hier [0] FYI "PAM module may allow accessing with the credentials of another user" --> "... up to version 0.3.4 can allow broker-managed users to impersonate any other user managed by the same broker and perform any PAM operation with it, including authenticating as the ..." VG Bernd [0] https://github.com/ubuntu/authd/security/advisories/GHSA-x5q3-c8rm-w787 -- Bernd Kohler IT Center Abteilung: Netze RWTH Aachen University Wendlingweg 10 52074 Aachen Tel: +49 241 80-29793 Fax: +49 241 80-22666 kohler@itc.rwth-aachen.de www.itc.rwth-aachen.de Social Media Kanäle des IT Centers: https://blog.rwth-aachen.de/itc/ https://www.facebook.com/itcenterrwth https://www.linkedin.com/company/itcenterrwth https://twitter.com/ITCenterRWTH https://www.youtube.com/channel/UCKKDJJukeRwO0LP-ac8x8rQ
participants (1)
-
Bernd Kohler