Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2017-12197

Опубликовано: 18 янв. 2018
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 4
CVSS3: 6.5

Описание

It was found that libpam4j up to and including 1.8 did not properly validate user accounts when authenticating. A user with a valid password for a disabled account would be able to bypass security restrictions and possibly access sensitive information.

РелизСтатусПримечание
artful

released

1.4-2+deb8u1build0.17.10.1
devel

not-affected

1.4-3
esm-apps/xenial

released

1.4-2+deb8u1build0.16.04.1
esm-infra-legacy/trusty

DNE

trusty/esm was DNE [trusty was released [1.4-2+deb8u1build0.14.04.1]]
precise/esm

DNE

trusty

released

1.4-2+deb8u1build0.14.04.1
trusty/esm

DNE

trusty was released [1.4-2+deb8u1build0.14.04.1]
upstream

needs-triage

xenial

released

1.4-2+deb8u1build0.16.04.1
zesty

released

1.4-2+deb8u1build0.17.04.1

Показывать по

EPSS

Процентиль: 62%
0.00427
Низкий

4 Medium

CVSS2

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.3
redhat
больше 8 лет назад

It was found that libpam4j up to and including 1.8 did not properly validate user accounts when authenticating. A user with a valid password for a disabled account would be able to bypass security restrictions and possibly access sensitive information.

CVSS3: 6.5
nvd
около 8 лет назад

It was found that libpam4j up to and including 1.8 did not properly validate user accounts when authenticating. A user with a valid password for a disabled account would be able to bypass security restrictions and possibly access sensitive information.

CVSS3: 6.5
debian
около 8 лет назад

It was found that libpam4j up to and including 1.8 did not properly va ...

CVSS3: 6.5
github
больше 3 лет назад

Improper Input Validation in libpam4j

EPSS

Процентиль: 62%
0.00427
Низкий

4 Medium

CVSS2

6.5 Medium

CVSS3