pam-pgsql: format string vulnerability
| Package(s): | pam-pgsql | CVE #(s): | CAN-2003-0672 | ||||
| Created: | August 11, 2003 | Updated: | October 1, 2003 | ||||
| Description: | Florian Zumbiehl reported a vulnerability in pam-pgsql whereby the username to be used for authentication is used as a format string when writing a log message. This vulnerability may allow an attacker to execute arbitrary code with the privileges of the program requesting PAM authentication. | ||||||
| Alerts: |
| ||||||
