CVE-2004-1340
libpam-radius-auth - information leak, integer underflow
EPSS 0.40%
Description
Debian GNU/Linux 3.0 installs the libpam-radius-auth package with the pam_radius_auth.conf set to be world-readable, which allows local users to obtain sensitive information.
How to fix CVE-2004-1340
To remediate CVE-2004-1340, upgrade the affected package to a fixed version below.
- Debian/libpam-radius-auth—upgrade to 1.3.16-1.1 or later
- Debian/libpam-radius-auth—upgrade to 1.3.14-1.3 or later
Is CVE-2004-1340 being exploited?
Low — EPSS is 0.4%, meaning exploitation activity has not been observed at scale.
Affected packages (2)
- from 0, < 1.3.16-1.1
- from 0, < 1.3.14-1.3