Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-268h-82rc-5x3h

Опубликовано: 08 июн. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 7.3

Описание

fprintd through 1.94.3 lacks a security attention mechanism, and thus unexpected actions might be authorized by "auth sufficient pam_fprintd.so" for Sudo.

fprintd through 1.94.3 lacks a security attention mechanism, and thus unexpected actions might be authorized by "auth sufficient pam_fprintd.so" for Sudo.

EPSS

Процентиль: 19%
0.00059
Низкий

7.3 High

CVSS3

Дефекты

CWE-287

Связанные уязвимости

CVSS3: 7.3
ubuntu
больше 1 года назад

fprintd through 1.94.3 lacks a security attention mechanism, and thus unexpected actions might be authorized by "auth sufficient pam_fprintd.so" for Sudo. NOTE: the supplier disputes this because they believe issue resolution would involve modifying the PAM configuration to restrict pam_fprintd.so to front-ends that implement a proper attention mechanism, not modifying pam_fprintd.so or fprintd.

redhat
больше 1 года назад

fprintd through 1.94.3 lacks a security attention mechanism, and thus unexpected actions might be authorized by "auth sufficient pam_fprintd.so" for Sudo. NOTE: the supplier disputes this because they believe issue resolution would involve modifying the PAM configuration to restrict pam_fprintd.so to front-ends that implement a proper attention mechanism, not modifying pam_fprintd.so or fprintd.

CVSS3: 7.3
nvd
больше 1 года назад

fprintd through 1.94.3 lacks a security attention mechanism, and thus unexpected actions might be authorized by "auth sufficient pam_fprintd.so" for Sudo. NOTE: the supplier disputes this because they believe issue resolution would involve modifying the PAM configuration to restrict pam_fprintd.so to front-ends that implement a proper attention mechanism, not modifying pam_fprintd.so or fprintd.

CVSS3: 7.3
debian
больше 1 года назад

fprintd through 1.94.3 lacks a security attention mechanism, and thus ...

EPSS

Процентиль: 19%
0.00059
Низкий

7.3 High

CVSS3

Дефекты

CWE-287