[CLSA-2025:1749571728] pam: Fix of 2 CVEs
Type:
security
Severity:
Moderate
Release date:
2025-06-10 16:08:52 UTC
Description:
- CVE-2024-10041: fix possibility of leakage of secret information stored in memory - CVE-2024-22365: fix potential DoS via mkfifo because the openat call lacks O_DIRECTORY
Updated packages:
  • pam-1.1.8-23.0.1.el7.tuxcare.els1.i686.rpm
    sha:1c3f06fa9db40705e4539ef2eaae401a7eb4061caaa3b5ab9740e59fb5d7aa4e
  • pam-1.1.8-23.0.1.el7.tuxcare.els1.x86_64.rpm
    sha:4a4404f8fa5a3db437d5f227fd42c9cf51ca6bd0127d4e03706af9fb269abe3f
  • pam-devel-1.1.8-23.0.1.el7.tuxcare.els1.i686.rpm
    sha:ed1228d17a6abc22839ba3d27fab7f37dcf7e29b796edb9cb3e15c2256d8c893
  • pam-devel-1.1.8-23.0.1.el7.tuxcare.els1.x86_64.rpm
    sha:ea092119c4b0dfc77716287d9ed64d6c84d5c006b226d145637ea3af4bb3f8ee
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.