CVE-2022-37030 Information

Description

Weak permissions on the configuration file in the PAM module in Grommunio Gromox 0.5 through 1.x before 1.28 allow a local unprivileged user in the gromox group to have the PAM stack execute arbitrary code upon loading the Gromox PAM module.

Reference

http://www.openwall.com/lists/oss-security/2022/08/04/1 https://bugzilla.suse.com/show_bug.cgi?id=1201949

Share on: