The _unix_run_helper_binary function in the pam_unix module in Linux-PAM (aka pam) before 1.2.1, when unable to directly access passwords, allows local users to enumerate usernames or cause a denial of service (hang) via a large password.
CVSS Details
- CVSS 3.1 Base Score: 6.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade pam-develUpgrade pam | Dec 1, 2016 | Aug 24, 2015 |
| Debian | — | Upgrade pam | Jul 30, 2024 | Aug 24, 2015 |
| F5 Big Ip | — | Update F5 BIG-IP to the latest version | Jun 17, 2026 | Oct 27, 2015 |
| Gentoo Linux | — | Upgrade sys-libs/pam. | Oct 30, 2017 | Aug 24, 2015 |
| Oracle_linux | — | Upgrade pamUpgrade pam-devel | Oct 16, 2024 | Aug 24, 2015 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Jun 25, 2015 |
| Suse | — | Upgrade pam-docUpgrade sles12-docker-imageUpgrade sles12sp1-docker-imageUpgrade pam-develUpgrade pam-32bitUpgrade pam-extraUpgrade pamUpgrade pam-x86Upgrade sles12sp2-docker-imageUpgrade pam-devel-32bitUpgrade pam-extra-32bit | Jun 21, 2016 | Aug 24, 2015 |
| Ubuntu | — | Upgrade libpam-modules | Mar 22, 2016 | Aug 24, 2015 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub