Login
Newsletter
Werbung

Sicherheit: Ausführen von Code mit höheren Privilegien in Pam-python (Aktualisierung)
Aktuelle Meldungen Distributionen
Name: Ausführen von Code mit höheren Privilegien in Pam-python (Aktualisierung)
ID: USN-4552-2
Distribution: Ubuntu
Plattformen: Ubuntu 16.04 LTS
Datum: Mo, 26. Oktober 2020, 22:57
Referenzen: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-16729
Applikationen: Pam-python
Update von: Ausführen von Code mit höheren Privilegien in Pam-python

Originalnachricht

This is an OpenPGP/MIME signed message (RFC 4880 and 3156)
--===============3584447971368555634==
Content-Type: multipart/signed; micalg=pgp-sha512;
protocol="application/pgp-signature";
boundary="j0SkDNamiq5dxDV6QDUicQYubDD61q1I6"

This is an OpenPGP/MIME signed message (RFC 4880 and 3156)
--j0SkDNamiq5dxDV6QDUicQYubDD61q1I6
Content-Type: multipart/mixed;
boundary="7nCMXLQ8qxPHF1q2MznquEA6DqWolugdz"

--7nCMXLQ8qxPHF1q2MznquEA6DqWolugdz
Content-Type: text/plain; charset=utf-8
Content-Language: en-U
Content-Transfer-Encoding: quoted-printable

==========================================================================
Ubuntu Security Notice USN-4552-2
October 21, 2020

pam-python vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 16.04 LTS

Summary:

Pam-python could be made to crash or run programs as an administrator
if certain environment variables are set.

Software Description:
- pam-python: Enables PAM modules to be written in Python

Details:

Malte Kraus discovered that Pam-python mishandled certain environment
variables. A local attacker could potentially use this vulnerability to
execute programs as root.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 16.04 LTS:
libpam-python 1.0.4-1.1+deb8u1build0.16.04.1

In general, a standard system update will make all the necessary changes.

References:
https://usn.ubuntu.com/4552-2
https://usn.ubuntu.com/4552-1
CVE-2019-16729

Package Information:
https://launchpad.net/ubuntu/+source/pam-python/1.0.4-1.1+deb8u1build0.16.04.1


--7nCMXLQ8qxPHF1q2MznquEA6DqWolugdz--

--j0SkDNamiq5dxDV6QDUicQYubDD61q1I6
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: OpenPGP digital signature
Content-Disposition: attachment; filename="signature.asc"

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEwZbe96kJeWh2OITRdyg1Qz0oXX0FAl+QjNUACgkQdyg1Qz0o
XX2hIQ/+PILanoNbcjJKNC9POvi0tNgQ4eMAngjOGD/goet/QNa+rbFUnnOwM4KP
I8E0oJLWiW3uo6P64pe+lPV0awxGt5LFRgIfvtRkD+lmjaVhQW71kM3BqdTYS4/G
hQHWEG6TQ+S6Y1ZgnP5lzQOoINa9393jimNdiuFSZkuJNkBWAK5/IEZDuP+zTIw1
5RQzlnNeVeb/Q/Z478cjWDIxrCq1m09bzQ0u/mVlTnfbxtrYTcfR2jHwOiKC2YvF
2E+sTMPh4/d22/mGHDwJp/CyQe9gPhDVLSINWFzH7MVshSZLam/Zb6UwxTzK3mQA
rosfFHLpspBlfEZ0n8yB+GRmG9GpJ/5kemk5pEJNacVsUSWX+LvZQplvWu3lezbL
hN80M00pNaIidfGvHCX00tdOPvuJNuimPIDgcsnlAo4GEgRo5H1EN7Xj6+2q9zZ8
nHVn2F54c2a/CJaNoU0eluR1Lern2y4YRfk0t425sUWSwkeSHADE4Vx5jNnc9BFf
E05VVtUBMxV3kNR0SHRy0N8omstkTOf1mEkKWbgnaeTuAvD2zRQ915dqJCW+kaVD
OxSP1tITyCkbdBpY3CyDwpEJWSYemyq863T2+iFeWm6CejbnbTejjrd3qI1oqBkX
Uu4Lx4bEWhvsh2o3I35JfMvegSvt5lb+8487wzdZZlvyvSRoYy8=
=1S7/
-----END PGP SIGNATURE-----

--j0SkDNamiq5dxDV6QDUicQYubDD61q1I6--


--===============3584447971368555634==
Content-Type: text/plain; charset="utf-8"
MIME-Version: 1.0
Content-Transfer-Encoding: base64
Content-Disposition: inline

LS0gCnVidW50dS1zZWN1cml0eS1hbm5vdW5jZSBtYWlsaW5nIGxpc3QKdWJ1bnR1LXNlY3VyaXR5
LWFubm91bmNlQGxpc3RzLnVidW50dS5jb20KTW9kaWZ5IHNldHRpbmdzIG9yIHVuc3Vic2NyaWJl
IGF0OiBodHRwczovL2xpc3RzLnVidW50dS5jb20vbWFpbG1hbi9saXN0aW5mby91YnVudHUtc2Vj
dXJpdHktYW5ub3VuY2UK

--===============3584447971368555634==--
Pro-Linux
Pro-Linux @Facebook
Neue Nachrichten
Werbung