Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:24158
HistoryApr 10, 2020 - 12:47 a.m.

Remote Code Execution (RCE)

2020-04-1000:47:50
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
12

0.0004 Low

EPSS

Percentile

10.3%

Pluggable Authentication Modules (PAM) is vulnerable to remote code execution (RCE). It was discovered that the pam_xauth module did not verify the return values of the setuid() and setgid() system calls. A local, unprivileged user could use this flaw to execute the xauth command with root privileges and make it read an arbitrary input file.

References