The Linux-PAM package before 1.5.2-6.1 for openSUSE Tumbleweed allows authentication bypass for SSH logins. The pam_access.so module doesn't correctly restrict login if a user tries to connect from an IP address that is not resolvable via DNS. In such conditions, a user with denied access to a machine can still get access. NOTE: the relevance of this issue is largely limited to openSUSE Tumbleweed and openSUSE Factory; it does not affect Linux-PAM upstream.
References
Link | Resource |
---|---|
https://www.suse.com/security/cve/CVE-2022-28321.html | Vendor Advisory |
http://download.opensuse.org/source/distribution/openSUSE-current/repo/oss/src/ | Patch Vendor Advisory |
https://bugzilla.suse.com/show_bug.cgi?id=1197654 | Issue Tracking Patch Vendor Advisory |
Configurations
Configuration 1 (hide)
AND |
|
History
22 Sep 2022, 14:52
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:linux-pam:linux-pam:*:*:*:*:*:*:*:* cpe:2.3:o:opensuse:tumbleweed:-:*:*:*:*:*:*:* |
|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.8 |
References | (MISC) http://download.opensuse.org/source/distribution/openSUSE-current/repo/oss/src/ - Patch, Vendor Advisory | |
References | (MISC) https://www.suse.com/security/cve/CVE-2022-28321.html - Vendor Advisory | |
References | (MISC) https://bugzilla.suse.com/show_bug.cgi?id=1197654 - Issue Tracking, Patch, Vendor Advisory | |
CWE | CWE-863 | |
First Time |
Opensuse
Opensuse tumbleweed Linux-pam linux-pam Linux-pam |
19 Sep 2022, 22:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2022-09-19 22:15
Updated : 2022-09-22 14:52
NVD link : CVE-2022-28321
Mitre link : CVE-2022-28321
JSON object : View
Products Affected
opensuse
- tumbleweed
linux-pam
- linux-pam
CWE
CWE-863
Incorrect Authorization