|
|
| |
|
| |
pam: denial of service, possible privilege escalation
| Package(s): | pam |
CVE #(s): | CVE-2009-0887
|
| Created: | March 23, 2009 |
Updated: | May 31, 2011 |
| Description: |
From the Mandriva advisory:
Integer signedness error in the _pam_StrTok function in
libpam/pam_misc.c in Linux-PAM (aka pam) 1.0.3 and earlier, when a
configuration file contains non-ASCII usernames, might allow remote
attackers to cause a denial of service, and might allow remote
authenticated users to obtain login access with a different user's
non-ASCII username, via a login attempt (CVE-2009-0887).
|
| Alerts: |
|
( Log in to post comments)
|
|
|