Pam-python could be made to crash or run programs as an administrator
if certain environment variables are set.
Software Description:
- pam-python: Enables PAM modules to be written in Python
Details:
Malte Kraus discovered that Pam-python mishandled certain environment
variables. A local attacker could potentially use this vulnerability to
execute programs as root.
The problem can be corrected by updating your system to the following package versions: Ubuntu 16.04 LTS: libpam-python 1.0.4-1.1+deb8u1build0.16.04.1 In general, a standard system update will make all the necessary changes.
https://ubuntu.com/security/notices/USN-4552-2
https://ubuntu.com/security/notices/USN-4552-1
CVE-2019-16729
Get the latest Linux and open source security news straight to your inbox.