Re: [oss-security] Security vulnerability in fprintd

2024-06-14 Thread Mark Esler
MITRE responded: > Thank you for contacting us. The oss-security thread says: > >The discussed behavior completely depends on the PAM configuration >(which, in most cases, needs to be enabled by the user). If this is >considered an issue, then it cannot be resolved within fprintd (and >

Re: [oss-security] Security vulnerability in fprintd

2024-06-14 Thread Benjamin Cance
This seems to be a system administration and configuration problem rather than a built in issue. On Fri, Jun 14, 2024 at 09:52 Yaron Shahrabani wrote: > Thank you all for your response and care. > > I would like to point out that although I managed to demonstrate this > vulnerability with a virt

Re: [oss-security] Security vulnerability in fprintd

2024-06-14 Thread Yaron Shahrabani
Thank you all for your response and care. I would like to point out that although I managed to demonstrate this vulnerability with a virtual terminal in a graphical interface it also applies to TTY, so even if I don't have any graphical interface I can still exploit this vulnerability. Adding a g