A flaw was found in util-linux. Improper hostname canonicalization in the login(1) utility, when invoked with the -h option, can modify the supplied remote hostname before setting PAM_RHOST. A remote attacker could exploit this by providing a specially crafted hostname, potentially bypassing host-based Pluggable Authentication Modules (PAM) access control rules that rely on fully qualified domain names. This could lead to unauthorized access.
{
"binaries": [
{
"binary_name": "bsdextrautils",
"binary_version": "2.41-4ubuntu4.2"
},
{
"binary_name": "bsdutils",
"binary_version": "1:2.41-4ubuntu4.2"
},
{
"binary_name": "eject",
"binary_version": "2.41-4ubuntu4.2"
},
{
"binary_name": "fdisk",
"binary_version": "2.41-4ubuntu4.2"
},
{
"binary_name": "lastlog2",
"binary_version": "2.41-4ubuntu4.2"
},
{
"binary_name": "libblkid1",
"binary_version": "2.41-4ubuntu4.2"
},
{
"binary_name": "libfdisk1",
"binary_version": "2.41-4ubuntu4.2"
},
{
"binary_name": "liblastlog2-2",
"binary_version": "2.41-4ubuntu4.2"
},
{
"binary_name": "libmount1",
"binary_version": "2.41-4ubuntu4.2"
},
{
"binary_name": "libpam-lastlog2",
"binary_version": "2.41-4ubuntu4.2"
},
{
"binary_name": "libsmartcols1",
"binary_version": "2.41-4ubuntu4.2"
},
{
"binary_name": "libuuid1",
"binary_version": "2.41-4ubuntu4.2"
},
{
"binary_name": "login",
"binary_version": "1:4.16.0-2+really2.41-4ubuntu4.2"
},
{
"binary_name": "mount",
"binary_version": "2.41-4ubuntu4.2"
},
{
"binary_name": "rfkill",
"binary_version": "2.41-4ubuntu4.2"
},
{
"binary_name": "util-linux",
"binary_version": "2.41-4ubuntu4.2"
},
{
"binary_name": "util-linux-extra",
"binary_version": "2.41-4ubuntu4.2"
},
{
"binary_name": "util-linux-locales",
"binary_version": "2.41-4ubuntu4.2"
},
{
"binary_name": "uuid-runtime",
"binary_version": "2.41-4ubuntu4.2"
}
]
}
{
"binaries": [
{
"binary_name": "bsdextrautils",
"binary_version": "2.41.3-3ubuntu2"
},
{
"binary_name": "bsdutils",
"binary_version": "1:2.41.3-3ubuntu2"
},
{
"binary_name": "eject",
"binary_version": "2.41.3-3ubuntu2"
},
{
"binary_name": "fdisk",
"binary_version": "2.41.3-3ubuntu2"
},
{
"binary_name": "lastlog2",
"binary_version": "2.41.3-3ubuntu2"
},
{
"binary_name": "libblkid1",
"binary_version": "2.41.3-3ubuntu2"
},
{
"binary_name": "libfdisk1",
"binary_version": "2.41.3-3ubuntu2"
},
{
"binary_name": "liblastlog2-2",
"binary_version": "2.41.3-3ubuntu2"
},
{
"binary_name": "libmount1",
"binary_version": "2.41.3-3ubuntu2"
},
{
"binary_name": "libpam-lastlog2",
"binary_version": "2.41.3-3ubuntu2"
},
{
"binary_name": "libsmartcols1",
"binary_version": "2.41.3-3ubuntu2"
},
{
"binary_name": "libuuid1",
"binary_version": "2.41.3-3ubuntu2"
},
{
"binary_name": "login",
"binary_version": "1:4.16.0-2+really2.41.3-3ubuntu2"
},
{
"binary_name": "mount",
"binary_version": "2.41.3-3ubuntu2"
},
{
"binary_name": "rfkill",
"binary_version": "2.41.3-3ubuntu2"
},
{
"binary_name": "util-linux",
"binary_version": "2.41.3-3ubuntu2"
},
{
"binary_name": "util-linux-extra",
"binary_version": "2.41.3-3ubuntu2"
},
{
"binary_name": "util-linux-locales",
"binary_version": "2.41.3-3ubuntu2"
},
{
"binary_name": "uuid-runtime",
"binary_version": "2.41.3-3ubuntu2"
}
]
}