Vulnerability Description
libtac in pam_tacplus through 1.5.1 lacks a check for a failure of RAND_bytes()/RAND_pseudo_bytes(). This could lead to use of a non-random/predictable session_id.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Pam Tacplus Project | Pam Tacplus | <= 1.5.1 |
Related Weaknesses (CWE)
References
- https://github.com/kravietz/pam_tacplus/pull/163Third Party Advisory
- https://tools.ietf.org/html/rfc8907Technical DescriptionThird Party Advisory
- https://github.com/kravietz/pam_tacplus/pull/163Third Party Advisory
- https://tools.ietf.org/html/rfc8907Technical DescriptionThird Party Advisory
FAQ
What is CVE-2020-27743?
CVE-2020-27743 is a vulnerability with a CVSS score of 9.8 (CRITICAL). libtac in pam_tacplus through 1.5.1 lacks a check for a failure of RAND_bytes()/RAND_pseudo_bytes(). This could lead to use of a non-random/predictable session_id.
How severe is CVE-2020-27743?
CVE-2020-27743 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2020-27743?
Check the references section above for vendor advisories and patch information. Affected products include: Pam Tacplus Project Pam Tacplus.