Advisories ยป MGASA-2018-0234

Updated libpam4j package fixes security vulnerability

Publication date: 16 May 2018
Modification date: 16 May 2018
Type: security
Affected Mageia releases : 6
CVE: CVE-2017-12197

Description

It was discovered that libpam4j, a Java library wrapper for the
integration of PAM did not call pam_acct_mgmt() during authentication.
As such a user who has a valid password, but a deactivated or disabled
account could still log in (CVE-2017-12197).
                

References

SRPMS

6/core