Description
pam_unix.so in Linux-PAM 0.99.7.0 allows context-dependent attackers to log into accounts whose password hash, as stored in /etc/passwd or /etc/shadow, has only two characters.
CVSS vector
AV:L/AC:L/C:C/I:C/A:CExploitability: 3.9 | Impact: 10.0 Affected Packages2 packages
🔴Vulnerability Details
1GHSAGHSA-8cvf-cppf-5rc4: pam_unix↗2022-05-01 ▶ 💥Exploits & PoCs
1Exploit-DBCoreHTTP Web server 0.5.3.1 - Off-by-One Buffer Overflow↗2009-12-02 ▶ 📋Vendor Advisories
4Red Hattog-pegasus pam authentication buffer overflow↗2008-01-08 ▶ Red Hattog-pegasus pam authentication buffer overflow↗2008-01-07 ▶ DebianCVE-2007-0003: pam - pam_unix.so in Linux-PAM 0.99.7.0 allows context-dependent attackers to log into...↗2007 ▶ 💬Community
4BugzillaCVE-2007-1218 tcpdump denial of service↗2007-03-15 ▶ BugzillaCVE-2007-1218 tcpdump denial of service↗2007-03-15 ▶ BugzillaCVE-2007-1218 tcpdump denial of service↗2007-03-14 ▶ BugzillaCVE-2007-1218 tcpdump denial of service↗2007-03-14 ▶