|
|
| |
|
| |
pam: arbitrary code execution
| Package(s): | pam |
CVE #(s): | CVE-2011-3148
CVE-2011-3149
|
| Created: | October 24, 2011 |
Updated: | March 11, 2013 |
| Description: |
From the Debian advisory:
Kees Cook of the ChromeOS security team discovered a buffer overflow
in pam_env, a PAM module to set environment variables through the
PAM stack, which allowed the execution of arbitrary code. An additional
issue in argument parsing allows denial of service.
|
| Alerts: |
|
( Log in to post comments)
|
|
|