HIGH 7.1 Microsoft
CVE-2024-47191
pam_oath.so in oath-toolkit 2.6.7 through 2.6.11 before 2.6.12 allows root privilege escalation because in the context of PAM code running as root it mishandles usersfile access such as by calling fchown in the presence of a symlink.
Microsoft Security Update 2024-Oct: pam_oath.so in oath-toolkit 2.6.7 through 2.6.11 before 2.6.12 allows root privilege escalation because in the context of PAM code running as root it mishandles usersfile access such as by calling fchown in the presence of a symlink.
Affected Products
- azl3 oath-toolkit 2.6.9-2 on Azure Linux 3.0
- cbl2 oath-toolkit 2.6.7-3 on CBL Mariner 2.0
- cbl2 oath-toolkit 2.6.7-3 on CBL-Mariner 2.0
References
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-47191
- https://nvd.nist.gov/vuln/detail/CVE-2024-47191
This high severity vulnerability with a CVSS score of 7.1 was published on 2024-10-08 via Microsoft. Affected: azl3 oath-toolkit 2.6.9-2 on Azure Linux 3.0, cbl2 oath-toolkit 2.6.7-3 on CBL Mariner 2.0, cbl2 oath-toolkit 2.6.7-3 on CBL-Mariner 2.0.
vulnfeed aggregates 11356 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.