Read Time:22 Second

Fabian Vogt reported that the PAM module in oath-toolkit, a collection
of components to build one-time password authentication systems, does
not safely perform file operations in users’s home directories when
using the usersfile feature (allowing to place the OTP state in the home
directory of the to-be-authenticated user). A local user can take
advantage of this flaw for root privilege escalation.

https://security-tracker.debian.org/tracker/DSA-5784-1

Read More