漏洞信息详情
pam-python 安全漏洞
漏洞简介
pam-python是一款用于支持使用Python语言编写PAM(可插入身份验证模块)的软件包。
pam-python 1.0.7-1之前版本中存在安全漏洞。攻击者可利用该漏洞将权限提升至root。
漏洞公告
目前厂商已发布升级补丁以修复漏洞,详情请关注厂商主页:
https://www.python.org
参考网址
来源:DEBIAN
链接:https://www.debian.org/security/2019/dsa-4555
来源:MISC
链接:https://sourceforge.net/p/pam-python/code/ci/0247ab687b4347cc52859ca461fb0126dd7e2ebe/
来源:MLIST
链接:https://lists.debian.org/debian-lts-announce/2019/11/msg00020.html
来源:MISC
链接:https://tracker.debian.org/news/1066790/accepted-pam-python-107-1-source-amd64-all-into-unstable/
来源:bugzilla.suse.com
链接:https://bugzilla.suse.com/show_bug.cgi?id=1150510#c1
来源:UBUNTU
链接:https://usn.ubuntu.com/4552-2/
来源:UBUNTU
链接:https://usn.ubuntu.com/4552-1/
来源:www.debian.org
链接:https://www.debian.org/security/2019/dsa-4555
来源:lists.debian.org
链接:https://lists.debian.org/debian-lts-announce/2019/11/msg00020.html
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2020.3624/
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2019.4006/
来源:vigilance.fr
链接:https://vigilance.fr/vulnerability/pam-python-privilege-escalation-via-Default-Environment-Variable-30748
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2019.4428/
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/159691/Ubuntu-Security-Notice-USN-4552-2.html
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2020.3334/
来源:nvd.nist.gov
链接:https://nvd.nist.gov/vuln/detail/CVE-2019-16729
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/159755/Ubuntu-Security-Notice-USN-4552-3.html
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/159311/Ubuntu-Security-Notice-USN-4552-1.html
受影响实体
暂无
补丁
- pam-python 安全漏洞的修复措施<!--2019-9-24-->
还没有评论,来说两句吧...