Protect yourself against future threats.
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 =========================================================================== AUSCERT External Security Bulletin Redistribution ESB-2020.1989 libpam-tacplus security update 9 June 2020 =========================================================================== AusCERT Security Bulletin Summary --------------------------------- Product: libpam-tacplus Publisher: Debian Operating System: Debian GNU/Linux 8 Linux variants Impact/Access: Access Confidential Data -- Existing Account Resolution: Patch/Upgrade CVE Names: CVE-2020-13881 Original Bulletin: https://www.debian.org/lts/security/2020/dla-2239 Comment: This advisory references vulnerabilities in products which run on platforms other than Debian. It is recommended that administrators running libpam-tacplus check for an updated version of the software for their operating system. - --------------------------BEGIN INCLUDED TEXT-------------------- - -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Package : libpam-tacplus Version : 1.3.8-2+deb8u1 CVE ID : CVE-2020-13881 It was discovered that there was an issue in libpam-tacplus (a security module for using the TACACS+ authentication service) where shared secrets such as private server keys were being added in the clear to various logs. For Debian 8 "Jessie", this issue has been fixed in libpam-tacplus version 1.3.8-2+deb8u1. We recommend that you upgrade your libpam-tacplus packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS Regards, - - -- ,''`. : :' : Chris Lamb `. `'` lamby@debian.org / chris-lamb.co.uk `- - -----BEGIN PGP SIGNATURE----- iQIzBAEBCAAdFiEEwv5L0nHBObhsUz5GHpU+J9QxHlgFAl7eUqwACgkQHpU+J9Qx HlgKJQ/+MAJiP2J3TiC6KsVFBdj9fiHvwoIBDqVchX0CKe/GHs2DJ7khHqNtUgEY yNYTBwuiAr8YaU1xyLtyBhsZFOR7cywwS4dyc7RNCirssip9i9PAZrgzoXOfIUkz 8YuP++d/FzvCuKtQ9IXl75azQpripzzyYZ65pPfYBlOU4wF52jm5VGKpOS7JQtCK ezKeV6Rb/y6gapTup5C7ji7B24/N4iu7R3my9OROAFcJMw5EUn8aoPMFDaJ0ykC2 sbga/sJImT7cHs16UsdK7jassMCjIVyXMLOIkOPPyvhN7Ayipx/YEsOwrm7t2A0q 78vqtlncvwlBhN4rTpsm9tOh1fK8c81Nk1qHOJ40FF0MzaiWXVutvoEKxyEjjY7A Mt4ZN0KONuf38CRQNi4EkAE/3rxtTCb577p/HzAgSvKV5iKbAioAUZQww0rJvF0U bAoeXUq32KxTgNCRtLKU6A7ttUY94KAzOLwtOxSmyNz+i1Wx22Z71OmB+BF8VEck Z91PEAd0IL3XQBEEWV7RKYSryRveQL8ySyqWbUxN43FEJKvqDYQEu2+lTssMkd8B yxqiFMWOUqRLYjyTNDv7odWxwzMi205sAsw4S5zZflKRiZCvaaTa2pF4shiAyi3V 9Mmi9M6iIwH0PuMVaGW2z8zHYdtQRMBEMtaYxtZQM30cYCE1nkg= =KZU/ - -----END PGP SIGNATURE----- - --------------------------END INCLUDED TEXT-------------------- You have received this e-mail bulletin as a result of your organisation's registration with AusCERT. The mailing list you are subscribed to is maintained within your organisation, so if you do not wish to continue receiving these bulletins you should contact your local IT manager. If you do not know who that is, please send an email to auscert@auscert.org.au and we will forward your request to the appropriate person. NOTE: Third Party Rights This security bulletin is provided as a service to AusCERT's members. As AusCERT did not write the document quoted above, AusCERT has had no control over its content. The decision to follow or act on information or advice contained in this security bulletin is the responsibility of each user or organisation, and should be considered in accordance with your organisation's site policies and procedures. AusCERT takes no responsibility for consequences which may arise from following or acting on information or advice contained in this security bulletin. NOTE: This is only the original release of the security bulletin. It may not be updated when updates to the original are made. If downloading at a later date, it is recommended that the bulletin is retrieved directly from the author's website to ensure that the information is still current. Contact information for the authors of the original document is included in the Security Bulletin above. If you have any questions or need further information, please contact them directly. Previous advisories and external security bulletins can be retrieved from: https://www.auscert.org.au/bulletins/ =========================================================================== Australian Computer Emergency Response Team The University of Queensland Brisbane Qld 4072 Internet Email: auscert@auscert.org.au Facsimile: (07) 3365 7031 Telephone: (07) 3365 4417 (International: +61 7 3365 4417) AusCERT personnel answer during Queensland business hours which are GMT+10:00 (AEST). On call after hours for member emergencies only. =========================================================================== -----BEGIN PGP SIGNATURE----- Comment: http://www.auscert.org.au/render.html?it=1967 iQIVAwUBXt7VRONLKJtyKPYoAQh3nQ//chhb0xYTE+6s5emfeH6TPGgX9AjSueIR w7Zu6wQKlwIiDNtjzfQ6nhItgZMw/mViW4VDGhAFDvM1BQEkOq67Z4At/WOMg7qX p2R+zltwT5PGbiIWNhqcmlvnnNLKCrpwP734GJJfbetlKvaYktNO3s36JA2fQdVM Q9HmwSt2dzYmN9sfsK9fagQZC8C0gmZ8qC8iQgbWTPqkYBjoi/3+P5D4t4uLEB5h 8R9Q/gqc24v96Z6uYxFjxqBjh09IufXYSj53D1lU/oPl7pwCZ3YV3spAWKzftgx4 WMceeiqew/5iS8gQx4arMS5WC4uAqyJjEMRTpPBw/rwOqCShVK1IeiP+LbOO+EAo BPZAz7YRb/d8qj/9PcWCpkLePjvEB72o+h0SP8VK7abdvXnIluq/Tuc+EFV2aCRx 19O5hlgw4OByDZ5LNDhqmWX8DRDZFy7dew1GLEUXHGqqWyDhPKrvQtKrVjRoSmNh U4mbO32uxIHs5SHEdGZvDAfYgKUO7eld3tD01FVcka4mXUmci93W1+8omqpOnRY3 b+vAs0nx5IsqDoB6yh91bfKml49cz3TZ357zODuexE/einpl/UDP5Hp1njC0W8KH dToz0fxGHozRA51adD7dc1Clu99350oldURa1JvIKUt5FvO7iz/JyyF4ImC1ya/b bUlExWZhYwM= =VaKD -----END PGP SIGNATURE-----