Multiple directory traversal vulnerabilities in pam_timestamp.c in the pam_timestamp module for Linux-PAM (aka pam) 1.1.8 allow local users to create arbitrary files or possibly bypass authentication via a .. (dot dot) in the (1) PAM_RUSER value to the get_ruser function or (2) PAM_TTY value to the check_tty function, which is used by the format_timestamp_name function.
CVSS Details
- CVSS 3.1 Base Score: 7.7
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade pam | Jul 30, 2024 | Apr 10, 2014 |
| Gentoo Linux | — | Upgrade sys-libs/pam. | Oct 30, 2017 | Apr 10, 2014 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Mar 24, 2014 |
| Suse | — | Upgrade pam-32bitUpgrade pam-docUpgrade pam-x86Upgrade pamUpgrade pam-devel-32bitUpgrade pam-devel | Dec 18, 2015 | Apr 10, 2014 |
| Ubuntu | — | Upgrade libpam-modules | Mar 22, 2016 | Apr 10, 2014 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub