SB2018121311 - OpenSUSE Linux update for pam
Published: December 13, 2018 Updated: December 13, 2018
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Denial of service (CVE-ID: CVE-2018-17953)
The vulnerability allows a remote attacker to cause DoS condition on the target system.
The vulnerability exists due to an incorrect variable in a SUSE specific patch for pam_access rule matching. A remote unauthenticated attacker can lead to pam_access rules not being applied (fail open).
Remediation
Install update from vendor's website.