A flaw was found in linux-pam. The module pam_namespace may use access user-controlled paths without proper protection, allowing local users to elevate their privileges to root via multiple symlink attacks and race conditions.
{ "binaries": [ { "binary_version": "1.4.0-11ubuntu2.6", "binary_name": "libpam-cracklib" }, { "binary_version": "1.4.0-11ubuntu2.6", "binary_name": "libpam-cracklib-dbgsym" }, { "binary_version": "1.4.0-11ubuntu2.6", "binary_name": "libpam-doc" }, { "binary_version": "1.4.0-11ubuntu2.6", "binary_name": "libpam-modules" }, { "binary_version": "1.4.0-11ubuntu2.6", "binary_name": "libpam-modules-bin" }, { "binary_version": "1.4.0-11ubuntu2.6", "binary_name": "libpam-modules-bin-dbgsym" }, { "binary_version": "1.4.0-11ubuntu2.6", "binary_name": "libpam-modules-dbgsym" }, { "binary_version": "1.4.0-11ubuntu2.6", "binary_name": "libpam-runtime" }, { "binary_version": "1.4.0-11ubuntu2.6", "binary_name": "libpam0g" }, { "binary_version": "1.4.0-11ubuntu2.6", "binary_name": "libpam0g-dbgsym" }, { "binary_version": "1.4.0-11ubuntu2.6", "binary_name": "libpam0g-dev" } ], "availability": "No subscription required" }
{ "binaries": [ { "binary_version": "1.5.3-5ubuntu5.4", "binary_name": "libpam-doc" }, { "binary_version": "1.5.3-5ubuntu5.4", "binary_name": "libpam-modules" }, { "binary_version": "1.5.3-5ubuntu5.4", "binary_name": "libpam-modules-bin" }, { "binary_version": "1.5.3-5ubuntu5.4", "binary_name": "libpam-modules-bin-dbgsym" }, { "binary_version": "1.5.3-5ubuntu5.4", "binary_name": "libpam-modules-dbgsym" }, { "binary_version": "1.5.3-5ubuntu5.4", "binary_name": "libpam-runtime" }, { "binary_version": "1.5.3-5ubuntu5.4", "binary_name": "libpam0g" }, { "binary_version": "1.5.3-5ubuntu5.4", "binary_name": "libpam0g-dbgsym" }, { "binary_version": "1.5.3-5ubuntu5.4", "binary_name": "libpam0g-dev" } ], "availability": "No subscription required" }
{ "binaries": [ { "binary_version": "1.5.3-7ubuntu4.3", "binary_name": "libpam-doc" }, { "binary_version": "1.5.3-7ubuntu4.3", "binary_name": "libpam-modules" }, { "binary_version": "1.5.3-7ubuntu4.3", "binary_name": "libpam-modules-bin" }, { "binary_version": "1.5.3-7ubuntu4.3", "binary_name": "libpam-modules-bin-dbgsym" }, { "binary_version": "1.5.3-7ubuntu4.3", "binary_name": "libpam-modules-dbgsym" }, { "binary_version": "1.5.3-7ubuntu4.3", "binary_name": "libpam-runtime" }, { "binary_version": "1.5.3-7ubuntu4.3", "binary_name": "libpam0g" }, { "binary_version": "1.5.3-7ubuntu4.3", "binary_name": "libpam0g-dbgsym" }, { "binary_version": "1.5.3-7ubuntu4.3", "binary_name": "libpam0g-dev" } ], "availability": "No subscription required" }