[Bug 242690] [NEW] <Ctrl+C> might allow to bypass authentication

Launchpad Bug Tracker 242690 at bugs.launchpad.net
Mon Jun 30 10:20:28 BST 2008


*** This bug is a security vulnerability ***

You have been subscribed to a public security bug by Thierry Carrez (tcarrez):

CVE-2008-2516
pam_sm_authenticate in pam_pgsql.c in libpam-pgsql 0.6.3 does not properly consider operator precedence when evaluating the success of a pam_get_pass function call, which allows local users to gain privileges via a SIGINT signal when this function is executing, as demonstrated by a CTRL-C sequence at a sudo password prompt in an "auth sufficient pam_pgsql.so" configuration.

Affected : gutsy, hardy, intrepid
Fixed in Debian 0.6.3-2, I'm working on a fakesync (our orig.tar.gz is borken)

** Affects: pam-pgsql (Ubuntu)
     Importance: High
         Status: Triaged

** Affects: pam-pgsql (Ubuntu Gutsy)
     Importance: High
         Status: Triaged

** Affects: pam-pgsql (Ubuntu Hardy)
     Importance: High
         Status: Triaged

** Affects: pam-pgsql (Ubuntu Intrepid)
     Importance: High
         Status: Triaged

** Affects: pam-pgsql (Debian)
     Importance: Unknown
         Status: Fix Released

-- 
<Ctrl+C> might allow to bypass authentication
https://bugs.launchpad.net/bugs/242690
You received this bug notification because you are a member of Ubuntu Sponsors for universe, which is a direct subscriber.



More information about the Ubuntu-universe-sponsors mailing list