pam_oath.so in oath-toolkit 2.6.7 through 2.6.11 before 2.6.12 allows root privilege escalation because, in the context of PAM code running as root, it mishandles usersfile access, such as by calling fchown in the presence of a symlink.
References
Configurations
No configuration.
History
No history.
Information
Published : 2024-10-09 05:15
Updated : 2024-11-21 09:39
NVD link : CVE-2024-47191
Mitre link : CVE-2024-47191
CVE.ORG link : CVE-2024-47191
JSON object : View
Products Affected
No product.
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')