USN-4521-1: pam_tacplus vulnerability
It was discovered that pamtacplus did not properly manage shared secrets if DEBUG loglevel and journald are used. A remote attacker could use this issue to expose sensitive information.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is USN-4521-1.
What is the title of the vulnerability?
The title of the vulnerability is 'USN-4521-1: pam_tacplus vulnerability'.
What is the description of the vulnerability?
The vulnerability is related to pam_tacplus not properly managing shared secrets if DEBUG loglevel and journald are used, which can allow a remote attacker to expose sensitive information.
Which software versions are affected?
The following versions of libpam-tacplus are affected: 1.3.8-2+deb8u1build0.20.04.1 (Ubuntu 20.04), 1.3.8-2+deb8u1build0.18.04.1 (Ubuntu 18.04), and 1.3.8-2+deb8u1build0.16.04.1 (Ubuntu 16.04).
How can I fix this vulnerability?
To fix this vulnerability, it is recommended to install the appropriate updates for libpam-tacplus. Please refer to the references for more information on the updates.