Candidate: CVE-2016-4422 PublicDate: 2016-05-06 17:59:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-4422 http://www.openwall.com/lists/oss-security/2016/05/01/2 https://bazaar.launchpad.net/~ltsp-upstream/ltsp/libpam-sshauth/revision/93/src/pam_sshauth.c (introduced in) Description: The pam_sm_authenticate function in pam_sshauth.c in libpam-sshauth might allow context-dependent attackers to bypass authentication or gain privileges via a system user account. Ubuntu-Description: Notes: sbeattie> simplified fix in oss-security posting Bugs: Priority: high Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H [9.8 CRITICAL] nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H [9.8 CRITICAL] Patches_libpam-sshauth: upstream: https://bazaar.launchpad.net/~ltsp-upstream/ltsp/libpam-sshauth/revision/114 upstream_libpam-sshauth: released (0.4.1-2) precise_libpam-sshauth: ignored (reached end-of-life) precise/esm_libpam-sshauth: DNE (precise was needs-triage) trusty_libpam-sshauth: released (0.3.1-1deb8u1build0.14.04.1) trusty/esm_libpam-sshauth: DNE (trusty was released [0.3.1-1deb8u1build0.14.04.1]) vivid/stable-phone-overlay_libpam-sshauth: DNE vivid/ubuntu-core_libpam-sshauth: DNE wily_libpam-sshauth: released (0.3.1-1ubuntu0.15.10.1) xenial_libpam-sshauth: released (0.3.1-1ubuntu2) yakkety_libpam-sshauth: not-affected (0.4.1-2) zesty_libpam-sshauth: not-affected (0.4.1-2) devel_libpam-sshauth: not-affected (0.4.1-2)