REDHAT-BUG-2442570: Low severity util-linux util-linux login vulnerability
Summary: Improper hostname canonicalization in util-linux login(1) when invoked with -h can modify the supplied remote hostname before setting PAMRHOST, potentially allowing bypass of host-based PAM access control rules (e.g., pamaccess) that rely on fully qualified domain names.
Requirements to exploit: An attacker must be able to access a remote login pathway that invokes login(1) with the -h <remotehost> option (e.g., telnet/rlogin-style daemons or custom wrappers). The target system must use PAM modules relying on PAMRHOST for authorization decisions (such as pamaccess) and have rules that distinguish between FQDNs and short hostnames. The local system hostname must share the same domain suffix as the attacker-supplied hostname.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2442570?
The severity of REDHAT-BUG-2442570 is classified as low.
What is the description of REDHAT-BUG-2442570?
REDHAT-BUG-2442570 describes improper hostname canonicalization in util-linux login which can modify remote hostname handling.
How does REDHAT-BUG-2442570 affect PAM access control?
REDHAT-BUG-2442570 can potentially allow bypassing of host-based PAM access control rules reliant on fully qualified domain names.
What software is affected by REDHAT-BUG-2442570?
The vulnerability REDHAT-BUG-2442570 affects the util-linux login component.
Is there a fix available for REDHAT-BUG-2442570?
The bug report for REDHAT-BUG-2442570 does not specify a fix, so users should monitor for updates from Red Hat.