CVE-2019-16729
published 2019-09-24CVE-2019-16729: pam-python before 1.0.7-1 has an issue in regard to the default environment variable handling of Python, which could allow for local root escalation in certain…
PriorityP335high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.36%
28.4th percentile
pam-python before 1.0.7-1 has an issue in regard to the default environment variable handling of Python, which could allow for local root escalation in certain PAM setups.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | pam-python | < pam-python 1.0.7-1 (bookworm) | pam-python 1.0.7-1 (bookworm) |
| pam-python_project | pam-python | < 1.0.7-1 | 1.0.7-1 |
| pam-python_project | pam-python | >= 0 < 1.0.7-1 | 1.0.7-1 |
| pam-python_project | pam-python | >= 0 < 1.0.7-1 | 1.0.7-1 |
| pam-python_project | pam-python | >= 0 < 1.0.7-1 | 1.0.7-1 |
| pam-python_project | pam-python | >= 0 < 1.0.7-1 | 1.0.7-1 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
osv7.8HIGH
vendor_debian7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Pam-python regression
vendor_ubuntu·2020-10-28
CVE-2019-16729 Pam-python regression
Title: Pam-python regression
Summary: USN-4552-1 and USN-4552-2 introduced a regression in Pam-python
USN-4552-1 and USN-4552-2 fixed a vulnerability in Pam-python. The update
introduced a regression which prevented PAM modules written in Python from
importing python modules from site-specific directories.
We apologize for the inconvenience.
Original advisory details:
Malte Kraus discovered that Pam-python mishandled certain environment variables.
A local attacker could potentially use this vulnerability to execute programs
as root.
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
Pam-python vulnerability
vendor_ubuntu·2020-10-21
CVE-2019-16729 Pam-python vulnerability
Title: Pam-python vulnerability
Summary: Pam-python could be made to crash or run programs as an administrator
if certain environment variables are set.
Malte Kraus discovered that Pam-python mishandled certain environment
variables. A local attacker could potentially use this vulnerability to
execute programs as root.
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
Pam-python vulnerability
vendor_ubuntu·2020-09-28
CVE-2019-16729 Pam-python vulnerability
Title: Pam-python vulnerability
Summary: Pam-python could be made to crash or run programs as an administrator
if certain environment variables are set.
Malte Kraus discovered that Pam-python mishandled certain environment variables.
A local attacker could potentially use this vulnerability to execute programs
as root.
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2019-16729: pam-python - pam-python before 1.0.7-1 has an issue in regard to the default environment vari...
vendor_debian·2019·CVSS 7.8
CVE-2019-16729 [HIGH] CVE-2019-16729: pam-python - pam-python before 1.0.7-1 has an issue in regard to the default environment vari...
pam-python before 1.0.7-1 has an issue in regard to the default environment variable handling of Python, which could allow for local root escalation in certain PAM setups.
Scope: local
bookworm: resolved (fixed in 1.0.7-1)
bullseye: resolved (fixed in 1.0.7-1)
forky: resolved (fixed in 1.0.7-1)
sid: resolved (fixed in 1.0.7-1)
trixie: resolved (fixed in 1.0.7-1)
GHSA
GHSA-fmm4-q9rf-m62f: pam-python before 1
ghsa_unreviewed·2022-05-24
CVE-2019-16729 [HIGH] GHSA-fmm4-q9rf-m62f: pam-python before 1
pam-python before 1.0.7-1 has an issue in regard to the default environment variable handling of Python, which could allow for local root escalation in certain PAM setups.
OSV
CVE-2019-16729: pam-python before 1
osv·2019-09-24·CVSS 7.8
CVE-2019-16729 [HIGH] CVE-2019-16729: pam-python before 1
pam-python before 1.0.7-1 has an issue in regard to the default environment variable handling of Python, which could allow for local root escalation in certain PAM setups.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://bugzilla.suse.com/show_bug.cgi?id=1150510#c1https://lists.debian.org/debian-lts-announce/2019/11/msg00020.htmlhttps://sourceforge.net/p/pam-python/code/ci/0247ab687b4347cc52859ca461fb0126dd7e2ebe/https://tracker.debian.org/news/1066790/accepted-pam-python-107-1-source-amd64-all-into-unstable/https://usn.ubuntu.com/4552-1/https://usn.ubuntu.com/4552-2/https://www.debian.org/security/2019/dsa-4555https://bugzilla.suse.com/show_bug.cgi?id=1150510#c1https://lists.debian.org/debian-lts-announce/2019/11/msg00020.htmlhttps://sourceforge.net/p/pam-python/code/ci/0247ab687b4347cc52859ca461fb0126dd7e2ebe/https://tracker.debian.org/news/1066790/accepted-pam-python-107-1-source-amd64-all-into-unstable/https://usn.ubuntu.com/4552-1/https://usn.ubuntu.com/4552-2/https://www.debian.org/security/2019/dsa-4555
2019-09-24
Published