<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 18:39:25 +0000</lastBuildDate>
    <item>
      <title>bdu:2024-07815</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2024-07815</link>
      <description>bdu:2024-07815</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2024-07815</guid>
    </item>
    <item>
      <title>EUVD-2026-203813</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-203813</link>
      <description>EUVD-2026-203813</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-203813</guid>
    </item>
    <item>
      <title>fkie_cve-2024-9313</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2024-9313</link>
      <description>&lt;p&gt;Authd PAM module before version 0.3.5 can allow broker-managed users to impersonate any other user managed by the same broker and perform any PAM operation with it, including authenticating as them.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Authd PAM module before version 0.3.5 can allow broker-managed users to impersonate any other user managed by the same broker and perform any PAM operation with it, including authenticating as them.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2024-9313</guid>
    </item>
    <item>
      <title>GHSA-x5q3-c8rm-w787 — PAM module may allow accessing with the credentials of another user</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-x5q3-c8rm-w787</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/ubuntu/authd&lt;/p&gt;
&lt;p&gt;Authd PAM module up to version 0.3.4 can allow broker-managed users to impersonate any other user managed by the same broker and perform any PAM operation with it, including authenticating as them.&lt;/p&gt;
&lt;p&gt;This is possible using tools such as `su`, `sudo` or `ssh` (and potentially others) that, so far, do not ensure that the PAM user at the end of the transaction is matching the one who initiated the transaction.&lt;/p&gt;
&lt;p&gt;Authd 0.3.5 fixes this by not allowing changing the user unless it was never set before in the PAM stack.&lt;/p&gt;
&lt;p&gt;`su` version that will include https://github.com/util-linux/util-linux/pull/3206 will not be affected
`ssh` version that will include https://github.com/openssh/openssh-portable/pull/521 will not be affected
`sudo` version that will include https://github.com/sudo-project/sudo/pull/412 will not be affected
`login` not affected
`passwd` not affected&lt;/p&gt;
&lt;p&gt;&amp;lt;details&amp;gt;
&amp;lt;summary&amp;gt;Old report&amp;lt;/summary&amp;gt;&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;An user can access as another user using its own credentials&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;I feel we’ve a security issue that is due to the fact that we allow changing the user in the cases in which that’s already provided by PAM, I’ve not tested this using the entra-id broker but it’s reproducible with the example one, but unless I’m missing something it should be independent from the broker in use.&lt;/p&gt;
&lt;p&gt;Basically, by going to the user selection page we allow to login as any user by entering the use own credentials.&lt;/p&gt;
&lt;p&gt;See for example: https://asciinema.org/a/VIcjpDImomaGu0wxsJJxNdmlf or…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/ubuntu/authd&lt;/p&gt;
&lt;p&gt;Authd PAM module up to version 0.3.4 can allow broker-managed users to impersonate any other user managed by the same broker and perform any PAM operation with it, including authenticating as them.&lt;/p&gt;
&lt;p&gt;This is possible using tools such as `su`, `sudo` or `ssh` (and potentially others) that, so far, do not ensure that the PAM user at the end of the transaction is matching the one who initiated the transaction.&lt;/p&gt;
&lt;p&gt;Authd 0.3.5 fixes this by not allowing changing the user unless it was never set before in the PAM stack.&lt;/p&gt;
&lt;p&gt;`su` version that will include https://github.com/util-linux/util-linux/pull/3206 will not be affected
`ssh` version that will include https://github.com/openssh/openssh-portable/pull/521 will not be affected
`sudo` version that will include https://github.com/sudo-project/sudo/pull/412 will not be affected
`login` not affected
`passwd` not affected&lt;/p&gt;
&lt;p&gt;&amp;lt;details&amp;gt;
&amp;lt;summary&amp;gt;Old report&amp;lt;/summary&amp;gt;&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;An user can access as another user using its own credentials&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;I feel we’ve a security issue that is due to the fact that we allow changing the user in the cases in which that’s already provided by PAM, I’ve not tested this using the entra-id broker but it’s reproducible with the example one, but unless I’m missing something it should be independent from the broker in use.&lt;/p&gt;
&lt;p&gt;Basically, by going to the user selection page we allow to login as any user by entering the use own credentials.&lt;/p&gt;
&lt;p&gt;See for example: https://asciinema.org/a/VIcjpDImomaGu0wxsJJxNdmlf or…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-x5q3-c8rm-w787</guid>
    </item>
    <item>
      <title>openSUSE-SU-2024:0350-1 — Security update for govulncheck-vulndb</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2024:0350-1</link>
      <description>&lt;p&gt;Security update for govulncheck-vulndb&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for govulncheck-vulndb&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2024:0350-1</guid>
    </item>
    <item>
      <title>SUSE-SU-2024:3911-1 — Security update for govulncheck-vulndb</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2024:3911-1</link>
      <description>&lt;p&gt;Security update for govulncheck-vulndb&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for govulncheck-vulndb&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2024:3911-1</guid>
    </item>
  </channel>
</rss>
