cbcvebase.
CVE-2014-2583
published 2014-04-10

CVE-2014-2583: Multiple directory traversal vulnerabilities in pam_timestamp.c in the pam_timestamp module for Linux-PAM (aka pam) 1.1.8 allow local users to create arbitrary…

PriorityP335medium5.8CVSS 2.0
AVNACMAuNCPIPAN
EPSS
4.12%
89.7th percentile
Multiple directory traversal vulnerabilities in pam_timestamp.c in the pam_timestamp module for Linux-PAM (aka pam) 1.1.8 allow local users to create arbitrary files or possibly bypass authentication via a .. (dot dot) in the (1) PAM_RUSER value to the get_ruser function or (2) PAM_TTY value to the check_tty function, which is used by the format_timestamp_name function.

Affected

8 ranges
VendorProductVersion rangeFixed in
debianpam< pam 1.1.8-3.1 (bookworm)pam 1.1.8-3.1 (bookworm)
linux-pamlinux-pam
pampam>= 0 < 1.1.8-3.11.1.8-3.1
pampam>= 0 < 1.1.8-3.11.1.8-3.1
pampam>= 0 < 1.1.8-3.11.1.8-3.1
pampam>= 0 < 1.1.8-3.11.1.8-3.1
pampam>= 0 < 1.1.8-1ubuntu2.21.1.8-1ubuntu2.2
pampam>= 0 < 1.1.8-1ubuntu2.11.1.8-1ubuntu2.1

CVSS provenance

nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:N
osv5.8MEDIUM
vendor_debian5.8LOW
vendor_redhat5.8MEDIUM
vendor_ubuntu4.3MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.