USN-7059-2: OATH Toolkit vulnerability
USN-7059-1 fixed a vulnerability in OATH Toolkit library. This update provides the corresponding update for Ubuntu 24.10. Original advisory details: Fabian Vogt discovered that OATH Toolkit incorrectly handled file permissions. A remote attacker could possibly use this issue to overwrite root owned files, leading to a privilege escalation attack. (CVE-2024-47191)
Affected Software
Event History
Frequently Asked Questions
What is the severity of USN-7059-2?
The vulnerability addressed in USN-7059-2 is classified as potentially high severity due to its implications on file permissions in the OATH Toolkit.
How do I fix USN-7059-2?
To fix USN-7059-2, update the OATH Toolkit library to version 2.6.11-3ubuntu1 on Ubuntu 24.10.
What software is affected by USN-7059-2?
USN-7059-2 affects the liboath-dev package in Ubuntu 24.10.
Who discovered the vulnerability in USN-7059-2?
The vulnerability in USN-7059-2 was discovered by researcher Fabian Vogt.
What type of vulnerability is addressed in USN-7059-2?
USN-7059-2 addresses a vulnerability related to improper handling of file permissions in the OATH Toolkit.