CVE-2015-3238Sensitive Information Exposure in Linux-pam

Severity
6.5MEDIUMNVD
OSV4.3
EPSS
3.0%
top 13.33%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 24
Latest updateMay 14

Description

The _unix_run_helper_binary function in the pam_unix module in Linux-PAM (aka pam) before 1.2.1, when unable to directly access passwords, allows local users to enumerate usernames or cause a denial of service (hang) via a large password.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:LExploitability: 3.9 | Impact: 2.5

Affected Packages5 packages

debiandebian/pam< pam 1.1.8-3.2 (bookworm)
Debianpam/pam< 1.1.8-3.2+3
Ubuntupam/pam< 1.1.8-1ubuntu2.2+1

🔴Vulnerability Details

4
GHSA
GHSA-6r75-hhm5-f689: The _unix_run_helper_binary function in the pam_unix module in Linux-PAM (aka pam) before 12022-05-14
OSV
pam regression2016-03-16
OSV
pam vulnerabilities2016-03-16
OSV
CVE-2015-3238: The _unix_run_helper_binary function in the pam_unix module in Linux-PAM (aka pam) before 12015-08-24

📋Vendor Advisories

5
Ubuntu
PAM regression2016-03-17
Ubuntu
PAM regression2016-03-16
Ubuntu
PAM vulnerabilities2016-03-16
Red Hat
pam: DoS/user enumeration due to blocking pipe in pam_unix module2015-06-25
Debian
CVE-2015-3238: pam - The _unix_run_helper_binary function in the pam_unix module in Linux-PAM (aka pa...2015

💬Community

2
Bugzilla
CVE-2016-6210 openssh: User enumeration via covert timing channel2016-07-18
Bugzilla
CVE-2015-3238 pam: DoS/user enumeration due to blocking pipe in pam_unix module2015-06-05
CVE-2015-3238 — Sensitive Information Exposure | cvebase