Release Info

Advisory: CLSA-2024:1712671933

OS: Ubuntu 16.04 ELS

Public date: 2024-04-09 10:12:15

Project: pam

Version: 1.1.8-3.2ubuntu2.3+tuxcare.els2

Errata link: https://errata.tuxcare.com/els_os/ubuntu16.04els/CLSA-2024-1712671933.html

Changelog

* SECURITY UPDATE: denial of service (blocked login process) via mkfifo - debian/patches-applied/CVE-2024-22365.patch: pam_namespace: protect_dir(): use O_DIRECTORY to prevent local DoS situations - CVE-2024-22365

Update

Update command: apt-get update apt-get --only-upgrade install pam*

Packages list

libpam-cracklib_1.1.8-3.2ubuntu2.3+tuxcare.els2_amd64.deb libpam-doc_1.1.8-3.2ubuntu2.3+tuxcare.els2_all.deb libpam-modules_1.1.8-3.2ubuntu2.3+tuxcare.els2_amd64.deb libpam-modules-bin_1.1.8-3.2ubuntu2.3+tuxcare.els2_amd64.deb libpam-runtime_1.1.8-3.2ubuntu2.3+tuxcare.els2_all.deb libpam0g_1.1.8-3.2ubuntu2.3+tuxcare.els2_amd64.deb libpam0g-dev_1.1.8-3.2ubuntu2.3+tuxcare.els2_amd64.deb

CVEs

CVE-2024-22365