May 22, 2012, 10:03:50 PM *
Welcome, Guest. Please login or register.

Login with username, password and session length
News: THC is up and running !
 

 
advertisement:

Pages: [1]
  Print  
Author Topic: USN828-1 : pam vulnerability  (Read 73 times)
zomgwtfbbq
Challenge Coder
Administrator
Hero Member
*****

Karma: +31340/-1
Posts: I am a geek!!


thc title: thc elite
thc points: 3315
challenges: (69/83)

View Profile
« on: September 10, 2009, 01:13:21 AM »
Share on FacebookFacebook Share

Synopsis :

These remote packages are missing security patches :
- libpam-cracklib
- libpam-doc
- libpam-modules
- libpam-runtime
- libpam0g
- libpam0g-dev

Description :

Russell Senior discovered that the system authentication module
selection mechanism for PAM did not safely handle an empty selection.
If an administrator had specifically removed the default list of modules
or failed to chose a module when operating debconf in a very unlikely
non-default configuration, PAM would allow any authentication attempt,
which could lead to remote attackers gaining access to a system with
arbitrary privileges.  This did not affect default Ubuntu installations.

Solution :

Upgrade to :
- libpam-cracklib-1.0.1-9ubuntu1.1 (Ubuntu 9.04)
- libpam-doc-1.0.1-9ubuntu1.1 (Ubuntu 9.04)
- libpam-modules-1.0.1-9ubuntu1.1 (Ubuntu 9.04)
- libpam-runtime-1.0.1-9ubuntu1.1 (Ubuntu 9.04)
- libpam0g-1.0.1-9ubuntu1.1 (Ubuntu 9.04)
- libpam0g-dev-1.0.1-9ubuntu1.1 (Ubuntu 9.04)

Risk factor :

High



only registered users with at least 25 hack challenge points can see links:
  click here in order to visit the hack challenges
More...
Logged


only registered users with at least 25 hack challenge points can see links:
  click here in order to visit the hack challenges


Ook al ben ik een slet toch houdt ik van je..
Pages: [1]
  Print  
 
Jump to:  


Related Topics
Subject Started by Replies Views Last post
RSS: USN1078-1 : logwatch vulnerability
Latest Tools and Files
zomgwtfbbq 0 86 Last post March 01, 2011, 06:20:00 PM
by zomgwtfbbq
RSS: USN1070-1 : bind9 vulnerability
Latest Tools and Files
zomgwtfbbq 0 57 Last post February 24, 2011, 05:30:20 PM
by zomgwtfbbq
RSS: USN1067-1 : telepathy-gabble vulnerability
Latest Tools and Files
zomgwtfbbq 0 101 Last post February 18, 2011, 07:32:01 PM
by zomgwtfbbq
RSS: USN1063-1 : qemu-kvm vulnerability
Latest Tools and Files
zomgwtfbbq 0 124 Last post February 15, 2011, 05:30:04 PM
by zomgwtfbbq
RSS: USN1051-1 : hplip vulnerability
Latest Tools and Files
zomgwtfbbq 0 51 Last post January 26, 2011, 04:32:23 PM
by zomgwtfbbq
RSS: USN1048-1 : tomcat6 vulnerability
Latest Tools and Files
zomgwtfbbq 0 85 Last post January 25, 2011, 04:30:22 PM
by zomgwtfbbq
RSS: USN1046-1 : sudo vulnerability
Latest Tools and Files
zomgwtfbbq 0 80 Last post January 21, 2011, 06:32:16 PM
by zomgwtfbbq
RSS: USN1033-1 : eucalyptus vulnerability
Latest Tools and Files
zomgwtfbbq 0 53 Last post December 17, 2010, 08:30:16 PM
by zomgwtfbbq
RSS: USN1032-1 : exim4 vulnerability
Latest Tools and Files
zomgwtfbbq 0 56 Last post December 12, 2010, 06:20:52 AM
by zomgwtfbbq
RSS: USN959-2 : pam vulnerability
Latest Tools and Files
zomgwtfbbq 0 50 Last post October 26, 2010, 05:23:35 PM
by zomgwtfbbq
RSS: USN1001-1 : lvm2 vulnerability
Latest Tools and Files
zomgwtfbbq 0 57 Last post October 07, 2010, 07:10:49 PM
by zomgwtfbbq
RSS: USN996-1 : mako vulnerability
Latest Tools and Files
zomgwtfbbq 0 49 Last post October 06, 2010, 02:30:06 PM
by zomgwtfbbq
RSS: USN985-1 : mountall vulnerability
Latest Tools and Files
zomgwtfbbq 0 61 Last post September 09, 2010, 06:10:38 PM
by zomgwtfbbq
RSS: USN984-1 : lftp vulnerability
Latest Tools and Files
zomgwtfbbq 0 47 Last post September 08, 2010, 03:02:03 PM
by zomgwtfbbq
RSS: USN982-1 : wget vulnerability
Latest Tools and Files
zomgwtfbbq 0 51 Last post September 03, 2010, 05:13:11 PM
by zomgwtfbbq
SMF Board hacked and modded by zomgwtfbekjam aka Rembo from Tools & Design