Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2013-7322
Description:usersfile.c in liboath in OATH Toolkit before 2.4.1 does not properly handle lines containing an invalid one-time-password (OTP) type and a user name in /etc/users.oath, which causes the wrong line to be updated when invalidating an OTP and allows context-dependent attackers to conduct replay attacks, as demonstrated by a commented out line when using libpam-oath.
Test IDs: 1.3.6.1.4.1.25623.1.0.867696   1.3.6.1.4.1.25623.1.1.10.2014.0101   1.3.6.1.4.1.25623.1.0.867528  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2013-7322
http://lists.nongnu.org/archive/html/oath-toolkit-help/2013-12/msg00000.html
http://lists.nongnu.org/archive/html/oath-toolkit-help/2013-12/msg00002.html
http://lists.nongnu.org/archive/html/oath-toolkit-help/2013-12/msg00003.html
http://seclists.org/oss-sec/2014/q1/296
XForce ISS Database: oath-toolkit-cve20137322-replay(91316)
https://exchange.xforce.ibmcloud.com/vulnerabilities/91316




© 1998-2025 E-Soft Inc. All rights reserved.