Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

openSUSE-SU-2021:1896-1

Опубликовано: 11 июл. 2021
Источник: suse-cvrf

Описание

Security update for pam_radius

This update for pam_radius fixes the following issues:

  • CVE-2015-9542: pam_radius: buffer overflow in password field (bsc#1163933)

Список пакетов

openSUSE Leap 15.3
pam_radius-1.4.0-3.3.1
pam_radius-32bit-1.4.0-3.3.1

Описание

add_password in pam_radius_auth.c in pam_radius 1.4.0 does not correctly check the length of the input password, and is vulnerable to a stack-based buffer overflow during memcpy(). An attacker could send a crafted password to an application (loading the pam_radius library) and crash it. Arbitrary code execution might be possible, depending on the application, C library, compiler, and other factors.


Затронутые продукты
openSUSE Leap 15.3:pam_radius-1.4.0-3.3.1
openSUSE Leap 15.3:pam_radius-32bit-1.4.0-3.3.1

Ссылки