CVE-2014-2583
published 2014-04-10CVE-2014-2583: Multiple directory traversal vulnerabilities in pam_timestamp.c in the pam_timestamp module for Linux-PAM (aka pam) 1.1.8 allow local users to create arbitrary…
PriorityP335medium5.8CVSS 2.0
AVNACMAuNCPIPAN
EPSS
4.12%
89.7th percentile
Multiple directory traversal vulnerabilities in pam_timestamp.c in the pam_timestamp module for Linux-PAM (aka pam) 1.1.8 allow local users to create arbitrary files or possibly bypass authentication via a .. (dot dot) in the (1) PAM_RUSER value to the get_ruser function or (2) PAM_TTY value to the check_tty function, which is used by the format_timestamp_name function.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | pam | < pam 1.1.8-3.1 (bookworm) | pam 1.1.8-3.1 (bookworm) |
| linux-pam | linux-pam | — | — |
| pam | pam | >= 0 < 1.1.8-3.1 | 1.1.8-3.1 |
| pam | pam | >= 0 < 1.1.8-3.1 | 1.1.8-3.1 |
| pam | pam | >= 0 < 1.1.8-3.1 | 1.1.8-3.1 |
| pam | pam | >= 0 < 1.1.8-3.1 | 1.1.8-3.1 |
| pam | pam | >= 0 < 1.1.8-1ubuntu2.2 | 1.1.8-1ubuntu2.2 |
| pam | pam | >= 0 < 1.1.8-1ubuntu2.1 | 1.1.8-1ubuntu2.1 |
CVSS provenance
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:N
osv5.8MEDIUM
vendor_debian5.8LOW
vendor_redhat5.8MEDIUM
vendor_ubuntu4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
PAM regression
vendor_ubuntu·2016-03-17·CVSS 4.3
[MEDIUM] PAM regression
Title: PAM regression
Summary: USN-2935-1 introduced a regression in PAM.
USN-2935-1 fixed vulnerabilities in PAM. The updates contained a packaging
change that prevented upgrades in certain multiarch environments. USN-2935-2
intended to fix the problem but was incomplete for Ubuntu 12.04 LTS. This
update fixes the problem in Ubuntu 12.04 LTS.
We apologize for the inconvenience.
Original advisory details:
It was discovered that the PAM pam_userdb module incorrectly used a
case-insensitive method when comparing hashed passwords. A local attacker
could possibly use this issue to make brute force attacks easier. This
issue only affected Ubuntu 12.04 LTS and Ubuntu 14.04 LTS. (CVE-2013-7041)
Sebastian Krahmer discovered that the PAM pam_timestamp module incorrectly
performed filtering. A
Ubuntu
PAM regression
vendor_ubuntu·2016-03-16·CVSS 4.3
[MEDIUM] PAM regression
Title: PAM regression
Summary: USN-2935-1 introduced a regression in PAM.
USN-2935-1 fixed vulnerabilities in PAM. The updates contained a packaging
change that prevented upgrades in certain multiarch environments. This
update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
It was discovered that the PAM pam_userdb module incorrectly used a
case-insensitive method when comparing hashed passwords. A local attacker
could possibly use this issue to make brute force attacks easier. This
issue only affected Ubuntu 12.04 LTS and Ubuntu 14.04 LTS. (CVE-2013-7041)
Sebastian Krahmer discovered that the PAM pam_timestamp module incorrectly
performed filtering. A local attacker could use this issue to create
arbitrary files, or possibly bypass authentication. T
Ubuntu
PAM vulnerabilities
vendor_ubuntu·2016-03-16·CVSS 4.3
CVE-2013-7041 [MEDIUM] PAM vulnerabilities
Title: PAM vulnerabilities
Summary: Several security issues were fixed in PAM.
It was discovered that the PAM pam_userdb module incorrectly used a
case-insensitive method when comparing hashed passwords. A local attacker
could possibly use this issue to make brute force attacks easier. This
issue only affected Ubuntu 12.04 LTS and Ubuntu 14.04 LTS. (CVE-2013-7041)
Sebastian Krahmer discovered that the PAM pam_timestamp module incorrectly
performed filtering. A local attacker could use this issue to create
arbitrary files, or possibly bypass authentication. This issue only
affected Ubuntu 12.04 LTS and Ubuntu 14.04 LTS. (CVE-2014-2583)
Sebastien Macke discovered that the PAM pam_unix module incorrectly handled
large passwords. A local attacker could possibly use this issue in certain
en
Red Hat
pam: path traversal issue in pam_timestamp's format_timestamp_name()
vendor_redhat·2014-03-24·CVSS 5.8
CVE-2014-2583 [MEDIUM] pam: path traversal issue in pam_timestamp's format_timestamp_name()
pam: path traversal issue in pam_timestamp's format_timestamp_name()
Multiple directory traversal vulnerabilities in pam_timestamp.c in the pam_timestamp module for Linux-PAM (aka pam) 1.1.8 allow local users to create arbitrary files or possibly bypass authentication via a .. (dot dot) in the (1) PAM_RUSER value to the get_ruser function or (2) PAM_TTY value to the check_tty function, which is used by the format_timestamp_name function.
Package: pam (Red Hat Enterprise Linux 5) - Will not fix
Package: pam (Red Hat Enterprise Linux 6) - Will not fix
Package: pam (Red Hat Enterprise Linux 7) - Not affected
Debian
CVE-2014-2583: pam - Multiple directory traversal vulnerabilities in pam_timestamp.c in the pam_times...
vendor_debian·2014·CVSS 5.8
CVE-2014-2583 [MEDIUM] CVE-2014-2583: pam - Multiple directory traversal vulnerabilities in pam_timestamp.c in the pam_times...
Multiple directory traversal vulnerabilities in pam_timestamp.c in the pam_timestamp module for Linux-PAM (aka pam) 1.1.8 allow local users to create arbitrary files or possibly bypass authentication via a .. (dot dot) in the (1) PAM_RUSER value to the get_ruser function or (2) PAM_TTY value to the check_tty function, which is used by the format_timestamp_name function.
Scope: local
bookworm: resolved (fixed in 1.1.8-3.1)
bullseye: resolved (fixed in 1.1.8-3.1)
forky: resolved (fixed in 1.1.8-3.1)
sid: resolved (fixed in 1.1.8-3.1)
trixie: resolved (fixed in 1.1.8-3.1)
GHSA
GHSA-p526-qhf4-2v4r: Multiple directory traversal vulnerabilities in pam_timestamp
ghsa_unreviewed·2022-05-14
CVE-2014-2583 [MEDIUM] CWE-22 GHSA-p526-qhf4-2v4r: Multiple directory traversal vulnerabilities in pam_timestamp
Multiple directory traversal vulnerabilities in pam_timestamp.c in the pam_timestamp module for Linux-PAM (aka pam) 1.1.8 allow local users to create arbitrary files or possibly bypass authentication via a .. (dot dot) in the (1) PAM_RUSER value to the get_ruser function or (2) PAM_TTY value to the check_tty function, which is used by the format_timestamp_name function.
OSV
pam regression
osv·2016-03-16·CVSS 4.3
[MEDIUM] pam regression
pam regression
USN-2935-1 fixed vulnerabilities in PAM. The updates contained a packaging
change that prevented upgrades in certain multiarch environments. This
update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
It was discovered that the PAM pam_userdb module incorrectly used a
case-insensitive method when comparing hashed passwords. A local attacker
could possibly use this issue to make brute force attacks easier. This
issue only affected Ubuntu 12.04 LTS and Ubuntu 14.04 LTS. (CVE-2013-7041)
Sebastian Krahmer discovered that the PAM pam_timestamp module incorrectly
performed filtering. A local attacker could use this issue to create
arbitrary files, or possibly bypass authentication. This issue only
affected Ubuntu 12.04 LTS and Ubuntu 14.04 LT
OSV
pam vulnerabilities
osv·2016-03-16·CVSS 4.3
CVE-2013-7041 [MEDIUM] pam vulnerabilities
pam vulnerabilities
It was discovered that the PAM pam_userdb module incorrectly used a
case-insensitive method when comparing hashed passwords. A local attacker
could possibly use this issue to make brute force attacks easier. This
issue only affected Ubuntu 12.04 LTS and Ubuntu 14.04 LTS. (CVE-2013-7041)
Sebastian Krahmer discovered that the PAM pam_timestamp module incorrectly
performed filtering. A local attacker could use this issue to create
arbitrary files, or possibly bypass authentication. This issue only
affected Ubuntu 12.04 LTS and Ubuntu 14.04 LTS. (CVE-2014-2583)
Sebastien Macke discovered that the PAM pam_unix module incorrectly handled
large passwords. A local attacker could possibly use this issue in certain
environments to enumerate usernames or cause a denial of servi
OSV
CVE-2014-2583: Multiple directory traversal vulnerabilities in pam_timestamp
osv·2014-04-10·CVSS 5.8
CVE-2014-2583 [MEDIUM] CVE-2014-2583: Multiple directory traversal vulnerabilities in pam_timestamp
Multiple directory traversal vulnerabilities in pam_timestamp.c in the pam_timestamp module for Linux-PAM (aka pam) 1.1.8 allow local users to create arbitrary files or possibly bypass authentication via a .. (dot dot) in the (1) PAM_RUSER value to the get_ruser function or (2) PAM_TTY value to the check_tty function, which is used by the format_timestamp_name function.
No detection rules found.
No public exploits indexed.
http://secunia.com/advisories/57317http://www.openwall.com/lists/oss-security/2014/03/24/5http://www.openwall.com/lists/oss-security/2014/03/26/10http://www.openwall.com/lists/oss-security/2014/03/31/6http://www.securityfocus.com/bid/66493http://www.ubuntu.com/usn/USN-2935-1http://www.ubuntu.com/usn/USN-2935-2http://www.ubuntu.com/usn/USN-2935-3https://git.fedorahosted.org/cgit/linux-pam.git/commit/?id=Linux-PAM-1_1_8-32-g9dcead8https://security.gentoo.org/glsa/201605-05http://secunia.com/advisories/57317http://www.openwall.com/lists/oss-security/2014/03/24/5http://www.openwall.com/lists/oss-security/2014/03/26/10http://www.openwall.com/lists/oss-security/2014/03/31/6http://www.securityfocus.com/bid/66493http://www.ubuntu.com/usn/USN-2935-1http://www.ubuntu.com/usn/USN-2935-2http://www.ubuntu.com/usn/USN-2935-3https://git.fedorahosted.org/cgit/linux-pam.git/commit/?id=Linux-PAM-1_1_8-32-g9dcead8https://security.gentoo.org/glsa/201605-05
2014-04-10
Published