CVE-2020-13881: High severity pam_tacplus vulnerability
Published Jun 6, 2020
·Updated
In support.c in pamtacplus 1.3.8 through 1.5.1, the TACACS+ shared secret gets logged via syslog if the DEBUG loglevel and journald are used.
Affected Software
11 affected componentsFixes available
ubuntu/libpam-tacplus<1.3.8-2+
1.3.8-2+
ubuntu/libpam-tacplus<1.3.8-2+
1.3.8-2+
ubuntu/libpam-tacplus<1.3.8-2+
1.3.8-2+
debian/libpam-tacplus
Pam Tacplus Project Pam Tacplus>=1.3.8<=1.5.1
Debian Debian Linux=8.0
Debian Debian Linux=9.0
Canonical Ubuntu Linux=16.04
Canonical Ubuntu Linux=18.04
Canonical Ubuntu Linux=20.04
Arista CloudVision Portal<2020.1.2
Remediation
Patch Available
Event History
Jun 6, 2020
CVE Published
via Ubuntu·12:00 AM
CVE Published
via MITRE·06:18 PM
Data Sourced
via MITRE·06:18 PM
Description
Aug 8, 2024
Data Sourced
via Launchpad·12:41 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2020-13881.
2
What is the severity of CVE-2020-13881?
The severity of CVE-2020-13881 is high with a CVSS score of 7.5.
3
Which software versions are affected by CVE-2020-13881?
The software versions affected by CVE-2020-13881 are pam_tacplus 1.3.8 through 1.5.1.
4
How can I fix CVE-2020-13881?
To fix CVE-2020-13881, update to version 1.3.8-2 or later of libpam-tacplus.
5
Are there any references related to CVE-2020-13881?
Yes, you can find references related to CVE-2020-13881 at the following links: [reference 1](http://www.openwall.com/lists/oss-security/2020/06/08/1), [reference 2](https://github.com/kravietz/pam_tacplus/commit/4a9852c31c2fd0c0e72fbb689a586aabcfb11cb0), [reference 3](https://github.com/kravietz/pam_tacplus/issues/149).