Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2003-0388Morgan Linux PAM vulnerability

7 documents6 sources
Severity
4.6MEDIUMNVD
EPSS
0.2%
top 63.94%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Timeline
PublishedJul 24
Latest updateApr 29

Description

pam_wheel in Linux-PAM 0.78, with the trust option enabled and the use_uid option disabled, allows local users to spoof log entries and gain privileges by causing getlogin() to return a spoofed user name.

CVSS vector

AV:L/AC:L/C:P/I:P/A:PExploitability: 3.9 | Impact: 6.4

Affected Packages2 packages

Patches

🔴Vulnerability Details

1
GHSA
GHSA-443h-2c59-36vf: pam_wheel in Linux-PAM 02022-04-29

💥Exploits & PoCs

1
Exploit-DB
Linux PAM 0.77 - Pam_Wheel Module 'getlogin() Username' Spoofing Privilege Escalation2003-06-16

📋Vendor Advisories

2
Red Hat
security flaw2003-06-16
Debian
CVE-2003-0388: pam - pam_wheel in Linux-PAM 0.78, with the trust option enabled and the use_uid optio...2003

💬Community

1
Bugzilla
CVE-2003-0388 security flaw2018-08-16
CVE-2003-0388 — Andrew Morgan Linux PAM vulnerability | cvebase