CVE-2016-4422: Critical severity libpam-sshauth vulnerability
The pamsmauthenticate function in pamsshauth.c in libpam-sshauth might allow context-dependent attackers to bypass authentication or gain privileges via a system user account.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-4422?
CVE-2016-4422 is classified as a medium severity vulnerability that can allow attackers to bypass authentication.
How do I fix CVE-2016-4422?
To fix CVE-2016-4422, you should update the libpam-sshauth package to the latest version or apply patches provided by your distribution.
Who is affected by CVE-2016-4422?
CVE-2016-4422 affects systems using the libpam-sshauth module, specifically on Debian GNU/Linux version 8.0.
What does CVE-2016-4422 exploit?
CVE-2016-4422 exploits a vulnerability in the pam_sm_authenticate function of libpam-sshauth, allowing potential privilege escalation.
Can CVE-2016-4422 be exploited remotely?
CVE-2016-4422 requires local access to the system, making it less likely to be exploited remotely.