7.8

CVE-2019-16729

pam-python before 1.0.7-1 has an issue in regard to the default environment variable handling of Python, which could allow for local root escalation in certain PAM setups.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Pam-python Project ≫ Pam-python Version < 1.0.7-1
Debian ≫ Debian Linux Version 8.0
Debian ≫ Debian Linux Version 9.0
Debian ≫ Debian Linux Version 10.0
Canonical ≫ Ubuntu Linux Version 16.04 SwEdition esm
Canonical ≫ Ubuntu Linux Version 18.04 SwEdition lts
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.36% 0.273
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
NIST 7.2 3.9 10
AV:L/AC:L/Au:N/C:C/I:C/A:C
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://bugzilla.suse.com/show_bug.cgi?id=1150510#c1
Third Party Advisory
Issue Tracking
https://lists.debian.org/debian-lts-announce/2019/11/msg00020.html
Third Party Advisory
Mailing List
https://sourceforge.net/p/pam-python/code/ci/0247ab687b4347cc52859ca461fb0126dd7e2ebe/
Patch
https://tracker.debian.org/news/1066790/accepted-pam-python-107-1-source-amd64-all-into-unstable/
Third Party Advisory
Mailing List
https://usn.ubuntu.com/4552-1/
Third Party Advisory
https://usn.ubuntu.com/4552-2/
Third Party Advisory
https://www.debian.org/security/2019/dsa-4555
Third Party Advisory