LWN.net Logo

pam: arbitrary code execution

Package(s):pam CVE #(s):CVE-2011-3148 CVE-2011-3149
Created:October 24, 2011 Updated:March 11, 2013
Description: From the Debian advisory:

Kees Cook of the ChromeOS security team discovered a buffer overflow in pam_env, a PAM module to set environment variables through the PAM stack, which allowed the execution of arbitrary code. An additional issue in argument parsing allows denial of service.

Alerts:
Fedora FEDORA-2011-16365 2011-11-25
Fedora FEDORA-2011-16390 2011-12-04
SUSE SUSE-SU-2011:1218-1 2011-11-04
SUSE SUSE-SU-2011:1207-1 2011-11-03
SUSE SUSE-SU-2011:1205-1 2011-11-03
SUSE SUSE-SU-2011:1209-1 2011-11-03
openSUSE openSUSE-SU-2011:1204-1 2011-11-03
openSUSE openSUSE-SU-2011:1208-1 2011-11-03
Ubuntu USN-1237-1 2011-10-24
Debian DSA-2326-1 2011-10-24
Gentoo 201206-31 2012-06-25
Red Hat RHSA-2013:0521-02 2013-02-21
Oracle ELSA-2013-0521 2013-02-25
Scientific Linux SL-pam-20130228 2013-02-28
CentOS CESA-2013:0521 2013-03-09

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds