CVE-2016-20014: Critical severity pam_tacplus vulnerability
Published Apr 21, 2022
·Updated
In pamtacplus.c in pamtacplus before 1.4.1, pamsmacctmgmt does not zero out the arep data structure.
Affected Software
1 affected component
Pam Tacplus Project Pam Tacplus<1.4.1
Remediation
Event History
Apr 21, 2022
CVE Published
via MITRE·03:58 AM
Data Sourced
via MITRE·03:58 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2016-20014.
2
What is the severity of CVE-2016-20014?
CVE-2016-20014 has a severity rating of critical (9.8).
3
What is the affected software for CVE-2016-20014?
The affected software for CVE-2016-20014 is Pam Tacplus (version up to and excluding 1.4.1).
4
What is the description of CVE-2016-20014?
CVE-2016-20014 is a vulnerability in pam_tacplus before 1.4.1, where pam_sm_acct_mgmt does not zero out the arep data structure.
5
How do I fix CVE-2016-20014?
To fix CVE-2016-20014, update Pam Tacplus to version 1.4.1 or later.