Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2017-12197

Опубликовано: 18 янв. 2018
Источник: debian

Описание

It was found that libpam4j up to and including 1.8 did not properly validate user accounts when authenticating. A user with a valid password for a disabled account would be able to bypass security restrictions and possibly access sensitive information.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
libpam4jfixed1.4-3package

Примечания

  • https://bugzilla.redhat.com/show_bug.cgi?id=1503103

  • https://github.com/kohsuke/libpam4j/issues/18

  • (Non-upstream) patch: https://github.com/letonez/libpam4j/commit/84f32f4001fc6bdcc125ccc959081de022d18b6d

Связанные уязвимости

CVSS3: 6.5
ubuntu
около 8 лет назад

It was found that libpam4j up to and including 1.8 did not properly validate user accounts when authenticating. A user with a valid password for a disabled account would be able to bypass security restrictions and possibly access sensitive information.

CVSS3: 4.3
redhat
больше 8 лет назад

It was found that libpam4j up to and including 1.8 did not properly validate user accounts when authenticating. A user with a valid password for a disabled account would be able to bypass security restrictions and possibly access sensitive information.

CVSS3: 6.5
nvd
около 8 лет назад

It was found that libpam4j up to and including 1.8 did not properly validate user accounts when authenticating. A user with a valid password for a disabled account would be able to bypass security restrictions and possibly access sensitive information.

CVSS3: 6.5
github
больше 3 лет назад

Improper Input Validation in libpam4j