Pam Tacplus Project Pam Tacplus 1.5.0

CPE Details

Pam Tacplus Project Pam Tacplus 1.5.0
1.5.0
2020-08-26
14h35 +00:00
2020-08-26
14h35 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:pam_tacplus_project:pam_tacplus:1.5.0:*:*:*:*:*:*:*

Informations

Vendor

pam_tacplus_project

Product

pam_tacplus

Version

1.5.0

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2020-27743 2020-10-26 20h40 +00:00 libtac in pam_tacplus through 1.5.1 lacks a check for a failure of RAND_bytes()/RAND_pseudo_bytes(). This could lead to use of a non-random/predictable session_id.
9.8
Critical
CVE-2020-13881 2020-06-06 16h18 +00:00 In support.c in pam_tacplus 1.3.8 through 1.5.1, the TACACS+ shared secret gets logged via syslog if the DEBUG loglevel and journald are used.
7.5
High