{"id":"UBUNTU-CVE-2013-7322","details":"usersfile.c in liboath in OATH Toolkit before 2.4.1 does not properly handle lines containing an invalid one-time-password (OTP) type and a user name in /etc/users.oath, which causes the wrong line to be updated when invalidating an OTP and allows context-dependent attackers to conduct replay attacks, as demonstrated by a commented out line when using libpam-oath.","modified":"2025-07-16T08:10:50.756030Z","published":"2014-03-09T13:16:00Z","withdrawn":"2025-07-18T16:42:57Z","upstream":["CVE-2013-7322"],"references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2013-7322"},{"type":"REPORT","url":"http://lists.nongnu.org/archive/html/oath-toolkit-help/2013-12/txtUm85v7Wqcy.txt"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2013-7322"}],"affected":[{"package":{"name":"oath-toolkit","ecosystem":"Ubuntu:16.04:LTS","purl":"pkg:deb/ubuntu/oath-toolkit@2.6.1-1?arch=source&distro=xenial"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.6.1-1"}]}],"ecosystem_specific":{"availability":"No subscription required","binaries":[{"binary_version":"2.6.1-1","binary_name":"liboath-dev"},{"binary_name":"liboath-dev-dbgsym","binary_version":"2.6.1-1"},{"binary_name":"liboath0","binary_version":"2.6.1-1"},{"binary_name":"liboath0-dbgsym","binary_version":"2.6.1-1"},{"binary_name":"libpam-oath","binary_version":"2.6.1-1"},{"binary_name":"libpam-oath-dbgsym","binary_version":"2.6.1-1"},{"binary_version":"2.6.1-1","binary_name":"oath-dbg"},{"binary_name":"oathtool","binary_version":"2.6.1-1"},{"binary_name":"oathtool-dbgsym","binary_version":"2.6.1-1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2013/UBUNTU-CVE-2013-7322.json"}},{"package":{"name":"oath-toolkit","ecosystem":"Ubuntu:18.04:LTS","purl":"pkg:deb/ubuntu/oath-toolkit@2.6.1-1?arch=source&distro=bionic"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.6.1-1"}]}],"ecosystem_specific":{"availability":"No subscription required","binaries":[{"binary_name":"liboath-dev","binary_version":"2.6.1-1"},{"binary_name":"liboath-dev-dbgsym","binary_version":"2.6.1-1"},{"binary_name":"liboath0","binary_version":"2.6.1-1"},{"binary_name":"liboath0-dbgsym","binary_version":"2.6.1-1"},{"binary_name":"libpam-oath","binary_version":"2.6.1-1"},{"binary_name":"libpam-oath-dbgsym","binary_version":"2.6.1-1"},{"binary_name":"oath-dbg","binary_version":"2.6.1-1"},{"binary_name":"oathtool","binary_version":"2.6.1-1"},{"binary_name":"oathtool-dbgsym","binary_version":"2.6.1-1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2013/UBUNTU-CVE-2013-7322.json"}}],"schema_version":"1.7.3","severity":[{"type":"Ubuntu","score":"medium"}]}