Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 523
Alerts This Week
Warning Icon 1 523

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -1 articles for you...
91

Gentoo: GLSA-202309-05 Medium: Yubico pam-u2f Remote Access Vulnerability

A vulnerability has been discovered in pam-u2f which could allow a local attacker to bypass PIN entry.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 202208-11 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Low Title: Yubico pam-u2f: Local PIN Bypass vulnerability Date: August 10, 2022 Bugs: #792270 ID: 202208-11 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= A vulnerability has been discovered in pam-u2f which could allow a local attacker to bypass PIN entry. Background ========= Yubico pam-u2f is a PAM module for FIDO2 and U2F keys. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 sys-auth/pam_u2f < 1.1.1 > = 1.1.1 Description ========== A logic issue in Yubico pam-u2f could result in the bypass of a PIN entry requirement when authenticating with FIDO2. Impact ===== An attacker with local access to certain applications using pam-u2f for authentication could incorrectly successfully authenticate without entering the authentication PIN. Workaround ========= There is no known workaround at this time. Resolution ========= All Yubico pam-u2f users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =sys-auth/pam_u2f-1.1.1" References ========= [ 1 ] CVE-2021-31924 https://nvd.nist.gov/vuln/detail/CVE-2021-31924 [ 2 ] YSA-2021-03 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/202208-11 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to This email address is being protected from spambots. You need JavaScript enabled to view it. or alternatively, you may file a bug at https://bugs.gentoo.org. License ====== Copyright 2022 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. https://creativecommons.org/licenses/by-sa/2.5/ . Investigate a minor vulnerability in pam-u2f on Gentoo Linux, which permits local users to bypass the PIN requirement, thereby jeopardizing the security of the authentication process.. Gentoo Security Advisory,PAM Module,Yubico PIN Bypass. . Severity: Low. LinuxSecurity.com Team

Calendar%202 Aug 10, 2022 Low Gentoo
172

Ubuntu 16.04 & 14.04: USN-3894-1 Critical: Gnome Keyring Threat

GNOME Keyring could be made to expose sensitive information.. =========================================================================Ubuntu Security Notice USN-3894-1 February 26, 2019 gnome-keyring vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 16.04 LTS - Ubuntu 14.04 LTS Summary: GNOME Keyring could be made to expose sensitive information. Software Description: - gnome-keyring: GNOME keyring services Details: It was discovered that GNOME Keyring incorrectly cleared out credentials supplied to the PAM module. A local attacker could possibly use this issue to discover login credentials. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 16.04 LTS: gnome-keyring 3.18.3-0ubuntu2.1 libpam-gnome-keyring 3.18.3-0ubuntu2.1 Ubuntu 14.04 LTS: gnome-keyring 3.10.1-1ubuntu4.4 libpam-gnome-keyring 3.10.1-1ubuntu4.4 After a standard system update you need to restart your session to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-3894-1 CVE-2018-20781 Package Information: https://launchpad.net/ubuntu/+source/gnome-keyring/3.18.3-0ubuntu2.1 https://launchpad.net/ubuntu/+source/gnome-keyring/3.10.1-1ubuntu4.4 . =========================================================================Ubuntu Security Notice USN-. gnome, keyring, expose, sensitive, information, =======================================. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Feb 26, 2019 Critical Ubuntu
100

SUSE: 2011:1209-1 Important: PAM Stack Overflow and DoS

An update that solves three vulnerabilities and has one An update that solves three vulnerabilities and has one An update that solves three vulnerabilities and has one errata is now available. errata is now available.. SUSE Security Update: Security update for pam ______________________________________________________________________________ Announcement ID: SUSE-SU-2011:1209-1 Rating: important References: #568833 #631802 #703187 #724480 Cross-References: CVE-2010-3316 CVE-2011-3148 CVE-2011-3149 Affected Products: SUSE Linux Enterprise Server 10 SP3 ______________________________________________________________________________ An update that solves three vulnerabilities and has one errata is now available. Description: The pam_env module is vulnerable to a stack overflow (CVE-2011-3148) and a DoS condition (CVE-2011-3149) when parsing users .pam_environment files. Additionally a missing return value check inside pam_xauth has been fixed (CVE-2010-3316). Security Issue references: * CVE-2011-3148 * CVE-2011-3149 * CVE-2010-3316 Package List: - SUSE Linux Enterprise Server 10 SP3 (i586 ia64 ppc s390x x86_64): pam-0.99.6.3-28.20.3.4 pam-devel-0.99.6.3-28.20.3.4 - SUSE Linux Enterprise Server 10 SP3 (s390x x86_64): pam-32bit-0.99.6.3-28.20.3.4 pam-devel-32bit-0.99.6.3-28.20.3.4 - SUSE Linux Enterprise Server 10 SP3 (ia64): pam-x86-0.99.6.3-28.20.3.4 - SUSE Linux Enterprise Server 10 SP3 (ppc): pam-64bit-0.99.6.3-28.20.3.4 pam-devel-64bit-0.99.6.3-28.20.3.4 References: https://www.suse.com/security/cve/CVE-2010-3316.html https://www.suse.com/security/cve/CVE-2011-3148.html https://www.suse.com/security/cve/CVE-2011-3149.html . SUSE Security Update: Security update for pam ______________________________________________________. update, solves, three, vulnerabilities. . Severity: Important.LinuxSecurity.com Team

Calendar%202 Nov 03, 2011 Important SuSE
87

Ubuntu: USN-4823-1 High: sudo Command Injection Vulnerability

Kees Cook of the ChromeOS security team discovered a buffer overflow in pam_env, a PAM module to set environment variables through the PAM stack, which allowed the execution of arbitrary code. An additional issue in argument parsing allows denial of service. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------- Debian Security Advisory DSA-2326-1 This email address is being protected from spambots. You need JavaScript enabled to view it. http://www.debian.org/security/ Moritz Muehlenhoff October 24, 2011 http://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : pam Vulnerability : several Problem type : remote Debian-specific: no CVE ID : CVE-2011-3148 CVE-2011-3149 Kees Cook of the ChromeOS security team discovered a buffer overflow in pam_env, a PAM module to set environment variables through the PAM stack, which allowed the execution of arbitrary code. An additional issue in argument parsing allows denial of service. The oldstable distribution (lenny) is not affected. For the stable distribution (squeeze), this problem has been fixed in version 1.1.1-6.1+squeeze1. For the unstable distribution (sid), this problem will be fixed soon (the impact in sid is limited to denial of service for both issues) We recommend that you upgrade your pam packages. Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: http://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . A critical vulnerability in the pam_env library permits unauthorized code execution and results in service disruption on Debian systems.. Debian Security Update, PAM Module, Buffer Overflow Issue. . LinuxSecurity.com Team

Calendar%202 Oct 24, 2011 Debian
98

Red Hat Enterprise Linux 6: RHSA-2010:0891-01 Moderate: pam Security Issue

Updated pam packages that fix three security issues are now available for Red Hat Enterprise Linux 6. The Red Hat Security Response Team has rated this update as having moderate [More...]. ==================================================================== Red Hat Security Advisory Synopsis: Moderate: pam security update Advisory ID: RHSA-2010:0891-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2010:0891.html Issue date: 2010-11-16 CVE Names: CVE-2010-3316 CVE-2010-3435 CVE-2010-3853 ==================================================================== 1. Summary: Updated pam packages that fix three security issues are now available for Red Hat Enterprise Linux 6. The Red Hat Security Response Team has rated this update as having moderate security impact. Common Vulnerability Scoring System (CVSS) base scores, which give detailed severity ratings, are available for each vulnerability from the CVE links in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux Desktop (v. 6) - i386, x86_64 Red Hat Enterprise Linux Desktop Optional (v. 6) - i386, x86_64 Red Hat Enterprise Linux HPC Node (v. 6) - x86_64 Red Hat Enterprise Linux HPC Node Optional (v. 6) - x86_64 Red Hat Enterprise Linux Server (v. 6) - i386, ppc64, s390x, x86_64 Red Hat Enterprise Linux Workstation (v. 6) - i386, x86_64 3. Description: Pluggable Authentication Modules (PAM) provide a system whereby administrators can set up authentication policies without having to recompile programs that handle authentication. It was discovered that the pam_namespace module executed the external script namespace.init with an unchanged environment inherited from an application calling PAM. In cases where such an environment was untrusted (for example, when pam_namespace was configured for setuid applications such as su or sudo), a local, unprivileged user could possibly use this flaw to escalate their privileges.(CVE-2010-3853) It was discovered that the pam_env and pam_mail modules used root privileges while accessing user's files. A local, unprivileged user could use this flaw to obtain information, from the lines that have the KEY=VALUE format expected by pam_env, from an arbitrary file. Also, in certain configurations, a local, unprivileged user using a service for which the pam_mail module was configured for, could use this flaw to obtain limited information about files or directories that they do not have access to. (CVE-2010-3435) Note: As part of the fix for CVE-2010-3435, this update changes the default value of pam_env's configuration option user_readenv to 0, causing the module to not read user's ~/.pam_environment configuration file by default, as reading it may introduce unexpected changes to the environment of the service using PAM, or PAM modules consulted after pam_env. It was discovered that the pam_xauth module did not verify the return values of the setuid() and setgid() system calls. A local, unprivileged user could use this flaw to execute the xauth command with root privileges and make it read an arbitrary input file. (CVE-2010-3316) Red Hat would like to thank Sebastian Krahmer of the SuSE Security Team for reporting the CVE-2010-3435 issue. All pam users should upgrade to these updated packages, which contain backported patches to correct these issues. 4. Solution: Before applying this update, make sure all previously-released errata relevant to your system have been applied. This update is available via the Red Hat Network. Details on how to use the Red Hat Network to apply this update are available at 5. Bugs fixed (http://bugzilla.redhat.com/): 637898 - CVE-2010-3316 pam: pam_xauth missing return value checks from setuid() and similar calls 641335 - CVE-2010-3435 pam: pam_env and pam_mail accessing users' file with root privileges 643043 - CVE-2010-3853 pam: pam_namespace executes namespace.init with service's environment 6. Package List: Red Hat Enterprise Linux Desktop (v.6): Source: i386: pam-1.1.1-4.el6_0.1.i686.rpm pam-debuginfo-1.1.1-4.el6_0.1.i686.rpm x86_64: pam-1.1.1-4.el6_0.1.i686.rpm pam-1.1.1-4.el6_0.1.x86_64.rpm pam-debuginfo-1.1.1-4.el6_0.1.i686.rpm pam-debuginfo-1.1.1-4.el6_0.1.x86_64.rpm Red Hat Enterprise Linux Desktop Optional (v. 6): Source: i386: pam-debuginfo-1.1.1-4.el6_0.1.i686.rpm pam-devel-1.1.1-4.el6_0.1.i686.rpm x86_64: pam-debuginfo-1.1.1-4.el6_0.1.i686.rpm pam-debuginfo-1.1.1-4.el6_0.1.x86_64.rpm pam-devel-1.1.1-4.el6_0.1.i686.rpm pam-devel-1.1.1-4.el6_0.1.x86_64.rpm Red Hat Enterprise Linux HPC Node (v. 6): Source: x86_64: pam-1.1.1-4.el6_0.1.i686.rpm pam-1.1.1-4.el6_0.1.x86_64.rpm pam-debuginfo-1.1.1-4.el6_0.1.i686.rpm pam-debuginfo-1.1.1-4.el6_0.1.x86_64.rpm Red Hat Enterprise Linux HPC Node Optional (v. 6): Source: x86_64: pam-debuginfo-1.1.1-4.el6_0.1.i686.rpm pam-debuginfo-1.1.1-4.el6_0.1.x86_64.rpm pam-devel-1.1.1-4.el6_0.1.i686.rpm pam-devel-1.1.1-4.el6_0.1.x86_64.rpm Red Hat Enterprise Linux Server (v. 6): Source: i386: pam-1.1.1-4.el6_0.1.i686.rpm pam-debuginfo-1.1.1-4.el6_0.1.i686.rpm pam-devel-1.1.1-4.el6_0.1.i686.rpm ppc64: pam-1.1.1-4.el6_0.1.ppc.rpm pam-1.1.1-4.el6_0.1.ppc64.rpm pam-debuginfo-1.1.1-4.el6_0.1.ppc.rpm pam-debuginfo-1.1.1-4.el6_0.1.ppc64.rpm pam-devel-1.1.1-4.el6_0.1.ppc.rpm pam-devel-1.1.1-4.el6_0.1.ppc64.rpm s390x: pam-1.1.1-4.el6_0.1.s390.rpm pam-1.1.1-4.el6_0.1.s390x.rpm pam-debuginfo-1.1.1-4.el6_0.1.s390.rpm pam-debuginfo-1.1.1-4.el6_0.1.s390x.rpm pam-devel-1.1.1-4.el6_0.1.s390.rpm pam-devel-1.1.1-4.el6_0.1.s390x.rpm x86_64: pam-1.1.1-4.el6_0.1.i686.rpm pam-1.1.1-4.el6_0.1.x86_64.rpm pam-debuginfo-1.1.1-4.el6_0.1.i686.rpm pam-debuginfo-1.1.1-4.el6_0.1.x86_64.rpm pam-devel-1.1.1-4.el6_0.1.i686.rpm pam-devel-1.1.1-4.el6_0.1.x86_64.rpm Red Hat Enterprise Linux Workstation (v.6): Source: i386: pam-1.1.1-4.el6_0.1.i686.rpm pam-debuginfo-1.1.1-4.el6_0.1.i686.rpm pam-devel-1.1.1-4.el6_0.1.i686.rpm x86_64: pam-1.1.1-4.el6_0.1.i686.rpm pam-1.1.1-4.el6_0.1.x86_64.rpm pam-debuginfo-1.1.1-4.el6_0.1.i686.rpm pam-debuginfo-1.1.1-4.el6_0.1.x86_64.rpm pam-devel-1.1.1-4.el6_0.1.i686.rpm pam-devel-1.1.1-4.el6_0.1.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key#package 7. References: https://access.redhat.com/security/cve/CVE-2010-3316 https://access.redhat.com/security/cve/CVE-2010-3435 https://access.redhat.com/security/cve/CVE-2010-3853 https://access.redhat.com/security/updates/classification#moderate 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2010 Red Hat, Inc. . Notice issued for pam updates targeting multiple security vulnerabilities in Red Hat Enterprise Linux 6. Installation of updates is advised.. Red Hat Enterprise Linux,PAM Security Fix,Authentication Modules,Security Update,Module Exploit. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Nov 16, 2010 Important Red Hat
89

Fedora 10: 2009-3500 Critical: pam_ssh SSH Authentication Issue

. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2009-3500 2009-04-13 18:40:19 -------------------------------------------------------------------------------- Name : pam_ssh Product : Fedora 10 Version : 1.92 Release : 10.fc10 URL : http://sourceforge.net/projects/pam-ssh/ Summary : PAM module for use with SSH keys and ssh-agent Description : This PAM module provides single sign-on behavior for UNIX using SSH keys. Users are authenticated by decrypting their SSH private keys with the password provided. In the first PAM login session phase, an ssh-agent process is started and keys are added. The same agent is used for the following PAM sessions. In any case the appropriate environment variables are set in the session phase. -------------------------------------------------------------------------------- ChangeLog: -------------------------------------------------------------------------------- References: [ 1 ] Bug #492153 - CVE-2009-1273 pam_ssh: Password prompt varies for existent and non-existent users https://bugzilla.redhat.com/show_bug.cgi?id=492153 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update pam_ssh' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at http://fedoraproject.org/keys -------------------------------------------------------------------------------- _______________________________________________ Fedora-package-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ . Ubuntu 18.04 openldap patch improves user access and experience with secure connections, boosting authentication reliability andoverall system protection.. Fedora Update,pam_ssh module,SSH authentication updates,security improvements. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 May 02, 2009 Critical Fedora
200

Scientific Linux SL5.x Security Advisory: Moderate PAM Issues Resolved

Moderate: pam security, bug fix, and enhancement update. Date: Fri, 9 Nov 2007 16:38:46 -0600 Reply-To: Connie Sieh Sender: Security Errata for Scientific Linux From: Connie Sieh Subject: Security ERRATA for pam on SL5.x Comments: To: scientific Synopsis: Moderate: pam security, bug fix, and enhancement update CVE Names: CVE-2007-1716 CVE-2007-3102 Problem description: A flaw was found in the way pam_console set console device permissions. It was possible for various console devices to retain ownership of the console user after logging out, possibly leaking information to another local user. (CVE-2007-1716) A flaw was found in the way the PAM library wrote account names to the audit subsystem. An attacker could inject strings containing parts of audit messages which could possibly mislead or confuse audit log parsing tools. (CVE-2007-3102) As well, these updated packages fix the following bugs: * truncated MD5-hashed passwords in "/etc/shadow" were treated as valid, resulting in insecure and invalid passwords. * the pam_namespace module did not convert context names to raw format and did not unmount polyinstantiated directories in some cases. It also crashed when an unknown user name was used in "/etc/security/namespace.conf", the pam_namespace configuration file. * the pam_selinux module was not relabeling the controlling tty correctly, and in some cases it did not send complete information about user role and level change to the audit subsystem. These updated packages add the following enhancements: * pam_limits module now supports parsing additional config files placed into the /etc/security/limits.d/ directory. These files are read after the main configuration file. * the modules pam_limits, pam_access, and pam_time now send a message to the audit subsystem when a user is denied access based on the number of login sessions, origin of user, and time of login. * pam_unix module security properties were improved.Functionality in the setuid helper binary, unix_chkpwd, which was not required for user authentication, was moved to a new non-setuid helper binary, unix_update. SL5.x SRPMS: pam-0.99.6.2-3.26.el5.src.rpm i386: pam-0.99.6.2-3.26.el5.i386.rpm pam-devel-0.99.6.2-3.26.el5.i386.rpm x86_64: pam-0.99.6.2-3.26.el5.i386.rpm pam-0.99.6.2-3.26.el5.x86_64.rpm pam-devel-0.99.6.2-3.26.el5.i386.rpm pam-devel-0.99.6.2-3.26.el5.x86_64.rpm -Connie Sieh -Troy Dawson . PAM security updates and improvements for Scientific Linux SL5.x including essential patches and bug fixes.. pam module fix, scientific linux security, access control enhancements. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Nov 09, 2007 Important Scientific Linux
98

Red Hat Enterprise Linux 2.1 RHSA-2004:304-01 Critical pam Escalation

If he pam_wheel module was used with the "trust" option enabled, but without the "use_uid" option, any local user could use PAM to gain access to a superuser account without supplying a password.. Red Hat Security Advisory Synopsis: Updated pam packages Advisory ID: RHSA-2004:304-01 Issue date: 2004-08-18 Updated on: 2004-08-18 Product: Red Hat Enterprise Linux Keywords: pam pam_wheel pam_lastlog CVE Names: CAN-2003-0388 - --------------------------------------------------------------------- 1. Summary: Updated pam packages that fix a security vulnerability are now available for Red Hat Enterprise Linux 2.1. 2. Relevant releases/architectures: Red Hat Enterprise Linux AS (Advanced Server) version 2.1 - i386, ia64 Red Hat Linux Advanced Workstation 2.1 - ia64 Red Hat Enterprise Linux ES version 2.1 - i386 Red Hat Enterprise Linux WS version 2.1 - i386 3. Problem description: PAM (Pluggable Authentication Modules) is a system security tool that allows system administrators to set an authentication policy without having to recompile programs that handle authentication. These updates fix a potential security problem present in the pam_wheel module. These updates correct a bug in the pam_lastlog module which prevented it from properly manipulating the /var/log/lastlog entry for users with very high user IDs. The pam_wheel module is used to restrict access to a particular service based on group membership. If the pam_wheel module was used with the "trust" option enabled, but without the "use_uid" option, any local user would be able to spoof the username returned by getlogin(). The user could therefore gain access to a superuser account without supplying a password. In Red Hat Enterprise Linux 2.1, pam_wheel is not used by default. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CAN-2003-0388 to this issue. When manipulating the entry in /var/log/lastlog, which corresponds to a given user, the pam_lastlogmodule calculates the location of the entry by multiplying the UID and the length of an entry in the file. On some systems, the result of this calculation would mistakenly be truncated to 32 bits for users with sufficiently high UIDs. All users of pam should upgrade to these updated packages, which resolve these issues. 4. Solution: Before applying this update, make sure that all previously-released errata relevant to your system have been applied. Use Red Hat Network to download and update your packages. To launch the Red Hat Update Agent, use the following command: up2date For information on how to install packages manually, refer to the following Web page for the System Administration or Customization guide specific to your system: https://docs.redhat.com/en/documentation/red_hat_enterprise_linux/10/ 5. Bug IDs fixed (http://bugzilla.redhat.com/ for more info): 98826 - CAN-2003-0388 pam_wheel uses getlogin in insecure fashion 6. RPMs required: Red Hat Enterprise Linux AS (Advanced Server) version 2.1: SRPMS: 5c78062a595e3443d22ca145b774cd34 pam-0.75-46.9.src.rpm i386: 1a72acefcb8b2c7bfb875f9024ae818b pam-0.75-46.9.i386.rpm e129fb8519d309ab26d3045bd91bb2e3 pam-devel-0.75-46.9.i386.rpm ia64: 851a5e5a7f78b4a4cbde060c62ab1e7d pam-0.75-46.9.ia64.rpm 3b23b14f7cfbcf2a73d21fd3a0b18bda pam-devel-0.75-46.9.ia64.rpm Red Hat Linux Advanced Workstation 2.1: SRPMS: 5c78062a595e3443d22ca145b774cd34 pam-0.75-46.9.src.rpm ia64: 851a5e5a7f78b4a4cbde060c62ab1e7d pam-0.75-46.9.ia64.rpm 3b23b14f7cfbcf2a73d21fd3a0b18bda pam-devel-0.75-46.9.ia64.rpm Red Hat Enterprise Linux ES version 2.1: SRPMS: 5c78062a595e3443d22ca145b774cd34 pam-0.75-46.9.src.rpm i386: 1a72acefcb8b2c7bfb875f9024ae818b pam-0.75-46.9.i386.rpm e129fb8519d309ab26d3045bd91bb2e3 pam-devel-0.75-46.9.i386.rpm Red Hat Enterprise Linux WS version 2.1: SRPMS: 5c78062a595e3443d22ca145b774cd34 pam-0.75-46.9.src.rpm i386: 1a72acefcb8b2c7bfb875f9024ae818b pam-0.75-46.9.i386.rpm e129fb8519d309ab26d3045bd91bb2e3 pam-devel-0.75-46.9.i386.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from 7. References: CVE -CVE-2003-0388 8. Contact: The Red Hat security contact is . More contact details at Copyright 2004 Red Hat, Inc. . Critical update for pam module in Red Hat addresses a serious local escalation flaw allowing unauthorized superuser access.. Red Hat, pam Module, Privilege Escalation, Security Advisory. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Aug 19, 2004 Critical Red Hat
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200