Integer signedness error in the _pam_StrTok function in libpam/pam_misc.c in Linux-PAM (aka pam) 1.0.3 and earlier, when a configuration file contains non-ASCII usernames, might allow remote attackers to cause a denial of service, and might allow remote authenticated users to obtain login access with a different user's non-ASCII username, via a login attempt.
CVSS Details
- CVSS 3.1 Base Score: 8.1
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade pam | Jul 30, 2024 | Mar 12, 2009 |
| Gentoo Linux | — | Upgrade sys-libs/pam. | Oct 30, 2017 | Mar 12, 2009 |
| Suse | — | Upgrade pam-x86Upgrade pam-32bitUpgrade pam-docUpgrade pam-devel-32bitUpgrade pamUpgrade pam-devel | Aug 9, 2024 | Jun 28, 2013 |
| Ubuntu | — | Upgrade libpam-modules | Nov 8, 2024 | Mar 12, 2009 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub