[CLSA-2024:1733245591] pam: Fix of CVE-2024-10963
Type:
security
Severity:
Important
Release date:
2024-12-03 17:06:37 UTC
Description:
- CVE-2024-10963: fix a flaw found in pam_access, where certain rules in its configuration file are mistakenly treated as hostnames. There is the new 'nodns' option which should be enabled to fix the CVE.
Updated packages:
  • pam-1.3.1-33.el8.tuxcare.els1.i686.rpm
    sha:83430e0672395e6c9a7f68e761b412f5a45d875d835f4f2f445ee98b7be379a5
  • pam-1.3.1-33.el8.tuxcare.els1.x86_64.rpm
    sha:f65b295669d589e0bc2f3af4d1e76d008881c4183e13fd710c40233e4800d259
  • pam-devel-1.3.1-33.el8.tuxcare.els1.i686.rpm
    sha:7b5f2aaed21bcc09732339f4f54cfd2b071cf462a9d0f1f624741e726da9bd5b
  • pam-devel-1.3.1-33.el8.tuxcare.els1.x86_64.rpm
    sha:1cb913cdc8e559f193e03b14f971ba379195b6b4599192711ec5e492753aa327
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.