LWN.net Logo

pam: denial of service, possible privilege escalation

Package(s):pam CVE #(s):CVE-2009-0887
Created:March 23, 2009 Updated:May 31, 2011
Description:

From the Mandriva advisory:

Integer signedness error in the _pam_StrTok function in libpam/pam_misc.c in Linux-PAM (aka pam) 1.0.3 and earlier, when a configuration file contains non-ASCII usernames, might allow remote attackers to cause a denial of service, and might allow remote authenticated users to obtain login access with a different user's non-ASCII username, via a login attempt (CVE-2009-0887).

Alerts:
Ubuntu USN-1140-2 2011-05-31
Ubuntu USN-1140-1 2011-05-30
Gentoo 200909-01 2009-09-07
Fedora FEDORA-2009-3231 2009-04-02
Fedora FEDORA-2009-3204 2009-04-02
Mandriva MDVSA-2009:077 2009-03-21

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds