CVE-2013-7041
published 2014-05-08CVE-2013-7041: The pam_userdb module for Pam uses a case-insensitive method to compare hashed passwords, which makes it easier for attackers to guess the password via a brute…
PriorityP421medium4.3CVSS 2.0
AVNACMAuNCPINAN
EPSS
2.48%
82.8th percentile
The pam_userdb module for Pam uses a case-insensitive method to compare hashed passwords, which makes it easier for attackers to guess the password via a brute force attack.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | pam | < pam 1.1.8-3.1 (bookworm) | pam 1.1.8-3.1 (bookworm) |
| pam | pam | >= 0 < 1.1.8-3.1 | 1.1.8-3.1 |
| pam | pam | >= 0 < 1.1.8-3.1 | 1.1.8-3.1 |
| pam | pam | >= 0 < 1.1.8-3.1 | 1.1.8-3.1 |
| pam | pam | >= 0 < 1.1.8-3.1 | 1.1.8-3.1 |
| pam | pam | >= 0 < 1.1.8-1ubuntu2.2 | 1.1.8-1ubuntu2.2 |
| pam | pam | >= 0 < 1.1.8-1ubuntu2.1 | 1.1.8-1ubuntu2.1 |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
osv4.3MEDIUM
vendor_debian4.3LOW
vendor_redhat4.3MEDIUM
vendor_ubuntu4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
PAM regression
vendor_ubuntu·2016-03-17·CVSS 4.3
[MEDIUM] PAM regression
Title: PAM regression
Summary: USN-2935-1 introduced a regression in PAM.
USN-2935-1 fixed vulnerabilities in PAM. The updates contained a packaging
change that prevented upgrades in certain multiarch environments. USN-2935-2
intended to fix the problem but was incomplete for Ubuntu 12.04 LTS. This
update fixes the problem in Ubuntu 12.04 LTS.
We apologize for the inconvenience.
Original advisory details:
It was discovered that the PAM pam_userdb module incorrectly used a
case-insensitive method when comparing hashed passwords. A local attacker
could possibly use this issue to make brute force attacks easier. This
issue only affected Ubuntu 12.04 LTS and Ubuntu 14.04 LTS. (CVE-2013-7041)
Sebastian Krahmer discovered that the PAM pam_timestamp module incorrectly
performed filtering. A
Ubuntu
PAM regression
vendor_ubuntu·2016-03-16·CVSS 4.3
[MEDIUM] PAM regression
Title: PAM regression
Summary: USN-2935-1 introduced a regression in PAM.
USN-2935-1 fixed vulnerabilities in PAM. The updates contained a packaging
change that prevented upgrades in certain multiarch environments. This
update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
It was discovered that the PAM pam_userdb module incorrectly used a
case-insensitive method when comparing hashed passwords. A local attacker
could possibly use this issue to make brute force attacks easier. This
issue only affected Ubuntu 12.04 LTS and Ubuntu 14.04 LTS. (CVE-2013-7041)
Sebastian Krahmer discovered that the PAM pam_timestamp module incorrectly
performed filtering. A local attacker could use this issue to create
arbitrary files, or possibly bypass authentication. T
Ubuntu
PAM vulnerabilities
vendor_ubuntu·2016-03-16·CVSS 4.3
CVE-2013-7041 [MEDIUM] PAM vulnerabilities
Title: PAM vulnerabilities
Summary: Several security issues were fixed in PAM.
It was discovered that the PAM pam_userdb module incorrectly used a
case-insensitive method when comparing hashed passwords. A local attacker
could possibly use this issue to make brute force attacks easier. This
issue only affected Ubuntu 12.04 LTS and Ubuntu 14.04 LTS. (CVE-2013-7041)
Sebastian Krahmer discovered that the PAM pam_timestamp module incorrectly
performed filtering. A local attacker could use this issue to create
arbitrary files, or possibly bypass authentication. This issue only
affected Ubuntu 12.04 LTS and Ubuntu 14.04 LTS. (CVE-2014-2583)
Sebastien Macke discovered that the PAM pam_unix module incorrectly handled
large passwords. A local attacker could possibly use this issue in certain
en
Red Hat
pam: pam_userdb case insensitive password hash comparison
vendor_redhat·2013-12-04·CVSS 4.3
CVE-2013-7041 [MEDIUM] pam: pam_userdb case insensitive password hash comparison
pam: pam_userdb case insensitive password hash comparison
The pam_userdb module for Pam uses a case-insensitive method to compare hashed passwords, which makes it easier for attackers to guess the password via a brute force attack.
Package: pam (Red Hat Enterprise Linux 5) - Will not fix
Package: pam (Red Hat Enterprise Linux 6) - Will not fix
Package: pam (Red Hat Enterprise Linux 7) - Not affected
Debian
CVE-2013-7041: pam - The pam_userdb module for Pam uses a case-insensitive method to compare hashed p...
vendor_debian·2013·CVSS 4.3
CVE-2013-7041 [MEDIUM] CVE-2013-7041: pam - The pam_userdb module for Pam uses a case-insensitive method to compare hashed p...
The pam_userdb module for Pam uses a case-insensitive method to compare hashed passwords, which makes it easier for attackers to guess the password via a brute force attack.
Scope: local
bookworm: resolved (fixed in 1.1.8-3.1)
bullseye: resolved (fixed in 1.1.8-3.1)
forky: resolved (fixed in 1.1.8-3.1)
sid: resolved (fixed in 1.1.8-3.1)
trixie: resolved (fixed in 1.1.8-3.1)
GHSA
GHSA-mcg8-3cr3-6hq9: The pam_userdb module for Pam uses a case-insensitive method to compare hashed passwords, which makes it easier for attackers to guess the password vi
ghsa_unreviewed·2022-05-17
CVE-2013-7041 [MEDIUM] GHSA-mcg8-3cr3-6hq9: The pam_userdb module for Pam uses a case-insensitive method to compare hashed passwords, which makes it easier for attackers to guess the password vi
The pam_userdb module for Pam uses a case-insensitive method to compare hashed passwords, which makes it easier for attackers to guess the password via a brute force attack.
OSV
pam regression
osv·2016-03-16·CVSS 4.3
[MEDIUM] pam regression
pam regression
USN-2935-1 fixed vulnerabilities in PAM. The updates contained a packaging
change that prevented upgrades in certain multiarch environments. This
update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
It was discovered that the PAM pam_userdb module incorrectly used a
case-insensitive method when comparing hashed passwords. A local attacker
could possibly use this issue to make brute force attacks easier. This
issue only affected Ubuntu 12.04 LTS and Ubuntu 14.04 LTS. (CVE-2013-7041)
Sebastian Krahmer discovered that the PAM pam_timestamp module incorrectly
performed filtering. A local attacker could use this issue to create
arbitrary files, or possibly bypass authentication. This issue only
affected Ubuntu 12.04 LTS and Ubuntu 14.04 LT
OSV
pam vulnerabilities
osv·2016-03-16·CVSS 4.3
CVE-2013-7041 [MEDIUM] pam vulnerabilities
pam vulnerabilities
It was discovered that the PAM pam_userdb module incorrectly used a
case-insensitive method when comparing hashed passwords. A local attacker
could possibly use this issue to make brute force attacks easier. This
issue only affected Ubuntu 12.04 LTS and Ubuntu 14.04 LTS. (CVE-2013-7041)
Sebastian Krahmer discovered that the PAM pam_timestamp module incorrectly
performed filtering. A local attacker could use this issue to create
arbitrary files, or possibly bypass authentication. This issue only
affected Ubuntu 12.04 LTS and Ubuntu 14.04 LTS. (CVE-2014-2583)
Sebastien Macke discovered that the PAM pam_unix module incorrectly handled
large passwords. A local attacker could possibly use this issue in certain
environments to enumerate usernames or cause a denial of servi
OSV
CVE-2013-7041: The pam_userdb module for Pam uses a case-insensitive method to compare hashed passwords, which makes it easier for attackers to guess the password vi
osv·2014-05-08·CVSS 4.3
CVE-2013-7041 [MEDIUM] CVE-2013-7041: The pam_userdb module for Pam uses a case-insensitive method to compare hashed passwords, which makes it easier for attackers to guess the password vi
The pam_userdb module for Pam uses a case-insensitive method to compare hashed passwords, which makes it easier for attackers to guess the password via a brute force attack.
No detection rules found.
No public exploits indexed.
http://www.openwall.com/lists/oss-security/2013/12/09/16http://www.openwall.com/lists/oss-security/2013/12/09/5http://www.securityfocus.com/bid/64180http://www.ubuntu.com/usn/USN-2935-1http://www.ubuntu.com/usn/USN-2935-2http://www.ubuntu.com/usn/USN-2935-3https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=731368https://bugzilla.redhat.com/show_bug.cgi?id=1038555https://security.gentoo.org/glsa/201605-05http://www.openwall.com/lists/oss-security/2013/12/09/16http://www.openwall.com/lists/oss-security/2013/12/09/5http://www.securityfocus.com/bid/64180http://www.ubuntu.com/usn/USN-2935-1http://www.ubuntu.com/usn/USN-2935-2http://www.ubuntu.com/usn/USN-2935-3https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=731368https://bugzilla.redhat.com/show_bug.cgi?id=1038555https://security.gentoo.org/glsa/201605-05
2014-05-08
Published