Possible fingerjacking vulnerability: CVE-2024-37408

Bug #2069490 reported by Yaron
258
This bug affects 1 person
Affects Status Importance Assigned to Milestone
pam (Ubuntu)
Triaged
Undecided
Unassigned

Bug Description

According to the aforementioned CVE, configuring fingerprint authorization for sudo poses a security threat.
It should either be mentioned as a warning or fixed otherwise.

Revision history for this message
Mark Esler (eslerm) wrote :

Is Ubuntu affected by default or is this an administrative choice?

https://www.openwall.com/lists/oss-security/2024/05/30/3

information type: Private Security → Public Security
Revision history for this message
Yaron (sh-yaron) wrote :

Administrative choice as part of pam-auth-update.

Changed in pam (Ubuntu):
status: New → Triaged
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.