CVE-2024-47191

HIGH

oath-toolkit <2.6.12 - Privilege Escalation

Title source: llm
STIX 2.1

Description

pam_oath.so in oath-toolkit 2.6.7 through 2.6.11 before 2.6.12 allows root privilege escalation because, in the context of PAM code running as root, it mishandles usersfile access, such as by calling fchown in the presence of a symlink.

Scores

CVSS v3 7.1
EPSS 0.0008
EPSS Percentile 22.4%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-22
Status published
Published Oct 09, 2024
Tracked Since Feb 18, 2026