7.8
CVE-2019-16729
- EPSS 0.36%
- Veröffentlicht 24.09.2019 05:15:11
- Zuletzt bearbeitet 21.11.2024 04:31:04
- Erkennungen
pam-python before 1.0.7-1 has an issue in regard to the default environment variable handling of Python, which could allow for local root escalation in certain PAM setups.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Pam-python Project ≫ Pam-python Version < 1.0.7-1
Debian ≫ Debian Linux Version 8.0
Debian ≫ Debian Linux Version 9.0
Debian ≫ Debian Linux Version 10.0
Canonical ≫ Ubuntu Linux Version 16.04 SwEdition esm
Canonical ≫ Ubuntu Linux Version 18.04 SwEdition lts
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.36% | 0.273 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
| NIST | 7.2 | 3.9 | 10 |
AV:L/AC:L/Au:N/C:C/I:C/A:C
|
https://bugzilla.suse.com/show_bug.cgi?id=1150510#c1
https://lists.debian.org/debian-lts-announce/2019/11/msg00020.html
https://sourceforge.net/p/pam-python/code/ci/0247ab687b4347cc52859ca461fb0126dd7e2ebe/
https://tracker.debian.org/news/1066790/accepted-pam-python-107-1-source-amd64-all-into-unstable/
https://usn.ubuntu.com/4552-1/
https://usn.ubuntu.com/4552-2/
https://www.debian.org/security/2019/dsa-4555