authorization

SLES 12 — pam_ssh — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — pam_ssh — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 18 March 2015 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE security advisory (see also SUSE bugzilla) Related CVEs: CVE-2009-1273 Upstream summary: pam_ssh 1.92 and possibly other versions, as used when PAM is compiled with USE=ssh, generates different error messages depending on whether the […]

Read more
SLES 12 — pam_radius — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — pam_radius — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 15 February 2015 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2020:1117-1 (see also SUSE bugzilla) Related CVEs: CVE-2015-9542 Upstream summary: add_password in pam_radius_auth.c in pam_radius 1.4.0 does not correctly check the length of the input password, and is vulnerable to a stack-based […]

Read more
SLES 12 — pam_krb5 — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — pam_krb5 — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 23 November 2014 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SR:2008:027 (see also SUSE bugzilla) Related CVEs: CVE-2008-3825 CVE-2009-1384 Upstream summary: pam_krb5 2.2.14 in Red Hat Enterprise Linux (RHEL) 5 and earlier, when the existing_ticket option is enabled, uses incorrect privileges when […]

Read more
CHAT