ALAS-2024-722


Amazon Linux 2023 Security Advisory: ALAS-2024-722
Advisory Release Date: 2024-10-10 03:02 Pacific
Advisory Updated Date: 2024-10-14 16:00 Pacific
Severity: Important

Issue Overview:

oath-toolkit: Local root exploit in a PAM module (CVE-2024-47191)


Affected Packages:

oath-toolkit


Issue Correction:
Run dnf update oath-toolkit --releasever 2023.6.20241010 to update your system.

New Packages:
aarch64:
    libpskc-debuginfo-2.6.12-1.amzn2023.0.1.aarch64
    oath-toolkit-debuginfo-2.6.12-1.amzn2023.0.1.aarch64
    oath-toolkit-debugsource-2.6.12-1.amzn2023.0.1.aarch64
    libpskc-devel-2.6.12-1.amzn2023.0.1.aarch64
    pskctool-debuginfo-2.6.12-1.amzn2023.0.1.aarch64
    pskctool-2.6.12-1.amzn2023.0.1.aarch64
    oathtool-debuginfo-2.6.12-1.amzn2023.0.1.aarch64
    libpskc-2.6.12-1.amzn2023.0.1.aarch64
    pam_oath-2.6.12-1.amzn2023.0.1.aarch64
    liboath-2.6.12-1.amzn2023.0.1.aarch64
    oathtool-2.6.12-1.amzn2023.0.1.aarch64
    liboath-devel-2.6.12-1.amzn2023.0.1.aarch64
    liboath-debuginfo-2.6.12-1.amzn2023.0.1.aarch64
    pam_oath-debuginfo-2.6.12-1.amzn2023.0.1.aarch64

noarch:
    libpskc-doc-2.6.12-1.amzn2023.0.1.noarch
    liboath-doc-2.6.12-1.amzn2023.0.1.noarch

src:
    oath-toolkit-2.6.12-1.amzn2023.0.1.src

x86_64:
    oathtool-debuginfo-2.6.12-1.amzn2023.0.1.x86_64
    oath-toolkit-debugsource-2.6.12-1.amzn2023.0.1.x86_64
    pskctool-2.6.12-1.amzn2023.0.1.x86_64
    libpskc-devel-2.6.12-1.amzn2023.0.1.x86_64
    pam_oath-debuginfo-2.6.12-1.amzn2023.0.1.x86_64
    libpskc-debuginfo-2.6.12-1.amzn2023.0.1.x86_64
    liboath-2.6.12-1.amzn2023.0.1.x86_64
    liboath-devel-2.6.12-1.amzn2023.0.1.x86_64
    pskctool-debuginfo-2.6.12-1.amzn2023.0.1.x86_64
    oathtool-2.6.12-1.amzn2023.0.1.x86_64
    oath-toolkit-debuginfo-2.6.12-1.amzn2023.0.1.x86_64
    liboath-debuginfo-2.6.12-1.amzn2023.0.1.x86_64
    pam_oath-2.6.12-1.amzn2023.0.1.x86_64
    libpskc-2.6.12-1.amzn2023.0.1.x86_64