Linuxsecurity
Ubuntu PAM Bypass Vulnerability Discovered
Article Content
A vulnerability in the Pluggable Authentication Modules (PAM) for Ubuntu was discovered by Juthawong Naisanguansee, allowing attackers to bypass authentication lockout restrictions. The issue arises when certain services invoke the account phase without prior authentication, leading to incorrect clearing of failed login attempt records. This flaw could enable unauthorized users to reset failed login counters, potentially compromising system security. The vulnerability affects multiple Ubuntu versions, including 24.04 LTS, 22.04 LTS, 20.04 LTS, and 18.04 LTS. Users are advised to update their systems to the latest package versions to mitigate the risk. A reboot is required after applying the updates to ensure changes take effect. The vulnerability is documented under Ubuntu Security Notice USN-8688-1. No active exploitation has been reported as of now.
Key Points: • PAM vulnerability allows bypass of authentication lockout restrictions. • Affected Ubuntu versions include 24.04, 22.04, 20.04, and 18.04 LTS. • Users must update and reboot systems to mitigate the risk.
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.