Show filters
3 Total Results
Displaying 1-3 of 3
Sort by:
Attacker Value
Unknown
CVE-2024-9312
Disclosure Date: October 10, 2024 (last updated October 12, 2024)
Authd, through version 0.3.6, did not sufficiently randomize user IDs to prevent collisions. A local attacker who can register user names could spoof another user's ID and gain their privileges.
0
Attacker Value
Unknown
CVE-2024-9313
Disclosure Date: October 03, 2024 (last updated October 03, 2024)
Authd PAM module before version 0.3.5 can allow broker-managed users to impersonate any other user managed by the same broker and perform any PAM operation with it, including authenticating as them.
0
Attacker Value
Unknown
CVE-2016-4982
Disclosure Date: July 17, 2017 (last updated November 26, 2024)
authd sets weak permissions for /etc/ident.key, which allows local users to obtain the key by leveraging a race condition between the creation of the key, and the chmod to protect it.
0