USN-7059-1: OATH Toolkit vulnerability
Published Oct 9, 2024
·Updated
Fabian Vogt discovered that OATH Toolkit incorrectly handled file permissions. A remote attacker could possibly use this issue to overwrite root owned files, leading to a privilege escalation attack. (CVE-2024-47191)
Affected Software
4 affected componentsFixes available
All of the following
ubuntu/liboath-dev<2.6.11-2.1ubuntu0.1
2.6.11-2.1ubuntu0.1
Ubuntu Ubuntu=24.04
All of the following
ubuntu/liboath-dev<2.6.7-3ubuntu0.1
2.6.7-3ubuntu0.1
Ubuntu Ubuntu=22.04
Event History
Oct 9, 2024
Advisory Published
via Ubuntu·12:00 AM
Frequently Asked Questions
1
What is the severity of USN-7059-1?
The severity of USN-7059-1 is significant as it can lead to privilege escalation due to improper file permission handling.
2
How do I fix USN-7059-1?
To fix USN-7059-1, update to the latest version of the liboath-dev package available for your Ubuntu version.
3
What versions of Ubuntu are affected by USN-7059-1?
USN-7059-1 affects Ubuntu 22.04 and Ubuntu 24.04 that include vulnerable versions of the liboath-dev package.
4
What is the cause of the vulnerability in USN-7059-1?
The cause of the vulnerability in USN-7059-1 is that OATH Toolkit incorrectly handled file permissions.
5
Can a remote attacker exploit USN-7059-1?
Yes, a remote attacker could potentially exploit USN-7059-1 to overwrite root owned files.