THREATINT

We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Zendesk (Helpdesk and Chat)

Ok

PUBLISHED

CVE-2024-37408

Reserved:2024-06-08
Published:2024-06-08
Updated:2024-06-14

Description

fprintd through 1.94.3 lacks a security attention mechanism, and thus unexpected actions might be authorized by "auth sufficient pam_fprintd.so" for Sudo. NOTE: the supplier disputes this because they believe issue resolution would involve modifying the PAM configuration to restrict pam_fprintd.so to front-ends that implement a proper attention mechanism, not modifying pam_fprintd.so or fprintd.

References

https://www.openwall.com/lists/oss-security/2024/05/30/3

https://lists.freedesktop.org/archives/fprint/2024-May/001231.html

https://gitlab.freedesktop.org/libfprint/fprintd/-/releases

https://www.openwall.com/lists/oss-security/2024/06/13/2

http://www.openwall.com/lists/oss-security/2024/06/13/3 ([oss-security] 20240613 Re: Security vulnerability in fprintd) mailing-list

http://www.openwall.com/lists/oss-security/2024/06/14/1 ([oss-security] 20240614 Re: Security vulnerability in fprintd) mailing-list

http://www.openwall.com/lists/oss-security/2024/06/14/2 ([oss-security] 20240614 Re: Security vulnerability in fprintd) mailing-list

http://www.openwall.com/lists/oss-security/2024/06/14/3 ([oss-security] 20240614 Re: Security vulnerability in fprintd) mailing-list

cve.org CVE-2024-37408

nvd.nist.gov CVE-2024-37408

Download JSON

Share this page
https://cve.threatint.com/CVE/CVE-2024-37408