Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-6jvj-39c6-mh4m

Опубликовано: 02 мая 2022
Источник: github
Github: Не прошло ревью

Описание

pam-auth-update for PAM, as used in Ubuntu 8.10 and 9.4, and Debian GNU/Linux, does not properly handle an "empty selection" for system authentication modules in certain rare configurations, which causes any attempt to be successful and allows remote attackers to bypass authentication.

pam-auth-update for PAM, as used in Ubuntu 8.10 and 9.4, and Debian GNU/Linux, does not properly handle an "empty selection" for system authentication modules in certain rare configurations, which causes any attempt to be successful and allows remote attackers to bypass authentication.

EPSS

Процентиль: 67%
0.00539
Низкий

Дефекты

CWE-287

Связанные уязвимости

ubuntu
больше 16 лет назад

pam-auth-update for PAM, as used in Ubuntu 8.10 and 9.4, and Debian GNU/Linux, does not properly handle an "empty selection" for system authentication modules in certain rare configurations, which causes any attempt to be successful and allows remote attackers to bypass authentication.

nvd
больше 16 лет назад

pam-auth-update for PAM, as used in Ubuntu 8.10 and 9.4, and Debian GNU/Linux, does not properly handle an "empty selection" for system authentication modules in certain rare configurations, which causes any attempt to be successful and allows remote attackers to bypass authentication.

debian
больше 16 лет назад

pam-auth-update for PAM, as used in Ubuntu 8.10 and 9.4, and Debian GN ...

EPSS

Процентиль: 67%
0.00539
Низкий

Дефекты

CWE-287