LWN.net Logo

opie: privilege escalation/code execution

Package(s):opie CVE #(s):CVE-2011-2489 CVE-2011-2490
Created:July 21, 2011 Updated:July 27, 2011
Description: From the Debian advisory:

Sebastian Krahmer discovered that opie, a system that makes it simple to use One-Time passwords in applications, is prone to a privilege escalation (CVE-2011-2490) and an off-by-one error, which can lead to the execution of arbitrary code (CVE-2011-2489).

Alerts:
openSUSE openSUSE-SU-2011:0848-1 2011-07-27
Debian DSA-2281-1 2011-07-21

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds