CVE-2015-3238
published 2015-08-24CVE-2015-3238: The _unix_run_helper_binary function in the pam_unix module in Linux-PAM (aka pam) before 1.2.1, when unable to directly access passwords, allows local users…
PriorityP430medium6.5CVSS 3.0
AVNACLPRNUINSUCLINAL
EPSS
2.71%
84.3th percentile
The _unix_run_helper_binary function in the pam_unix module in Linux-PAM (aka pam) before 1.2.1, when unable to directly access passwords, allows local users to enumerate usernames or cause a denial of service (hang) via a large password.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | pam | < pam 1.1.8-3.2 (bookworm) | pam 1.1.8-3.2 (bookworm) |
| linux-pam | linux-pam | <= 1.1.8 | — |
| oracle | sparc-opl_service_processor | <= 1121 | — |
| pam | pam | >= 0 < 1.1.8-3.2 | 1.1.8-3.2 |
| pam | pam | >= 0 < 1.1.8-3.2 | 1.1.8-3.2 |
| pam | pam | >= 0 < 1.1.8-3.2 | 1.1.8-3.2 |
| pam | pam | >= 0 < 1.1.8-3.2 | 1.1.8-3.2 |
| pam | pam | >= 0 < 1.1.8-1ubuntu2.2 | 1.1.8-1ubuntu2.2 |
| pam | pam | >= 0 < 1.1.8-1ubuntu2.1 | 1.1.8-1ubuntu2.1 |
CVSS provenance
nvdv3.06.5MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:P
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_redhat6.5MEDIUM
vendor_ubuntu4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
PAM regression
vendor_ubuntu·2016-03-17·CVSS 4.3
[MEDIUM] PAM regression
Title: PAM regression
Summary: USN-2935-1 introduced a regression in PAM.
USN-2935-1 fixed vulnerabilities in PAM. The updates contained a packaging
change that prevented upgrades in certain multiarch environments. USN-2935-2
intended to fix the problem but was incomplete for Ubuntu 12.04 LTS. This
update fixes the problem in Ubuntu 12.04 LTS.
We apologize for the inconvenience.
Original advisory details:
It was discovered that the PAM pam_userdb module incorrectly used a
case-insensitive method when comparing hashed passwords. A local attacker
could possibly use this issue to make brute force attacks easier. This
issue only affected Ubuntu 12.04 LTS and Ubuntu 14.04 LTS. (CVE-2013-7041)
Sebastian Krahmer discovered that the PAM pam_timestamp module incorrectly
performed filtering. A
Ubuntu
PAM regression
vendor_ubuntu·2016-03-16·CVSS 4.3
[MEDIUM] PAM regression
Title: PAM regression
Summary: USN-2935-1 introduced a regression in PAM.
USN-2935-1 fixed vulnerabilities in PAM. The updates contained a packaging
change that prevented upgrades in certain multiarch environments. This
update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
It was discovered that the PAM pam_userdb module incorrectly used a
case-insensitive method when comparing hashed passwords. A local attacker
could possibly use this issue to make brute force attacks easier. This
issue only affected Ubuntu 12.04 LTS and Ubuntu 14.04 LTS. (CVE-2013-7041)
Sebastian Krahmer discovered that the PAM pam_timestamp module incorrectly
performed filtering. A local attacker could use this issue to create
arbitrary files, or possibly bypass authentication. T
Ubuntu
PAM vulnerabilities
vendor_ubuntu·2016-03-16·CVSS 4.3
CVE-2013-7041 [MEDIUM] PAM vulnerabilities
Title: PAM vulnerabilities
Summary: Several security issues were fixed in PAM.
It was discovered that the PAM pam_userdb module incorrectly used a
case-insensitive method when comparing hashed passwords. A local attacker
could possibly use this issue to make brute force attacks easier. This
issue only affected Ubuntu 12.04 LTS and Ubuntu 14.04 LTS. (CVE-2013-7041)
Sebastian Krahmer discovered that the PAM pam_timestamp module incorrectly
performed filtering. A local attacker could use this issue to create
arbitrary files, or possibly bypass authentication. This issue only
affected Ubuntu 12.04 LTS and Ubuntu 14.04 LTS. (CVE-2014-2583)
Sebastien Macke discovered that the PAM pam_unix module incorrectly handled
large passwords. A local attacker could possibly use this issue in certain
en
Red Hat
pam: DoS/user enumeration due to blocking pipe in pam_unix module
vendor_redhat·2015-06-25·CVSS 6.5
CVE-2015-3238 [MEDIUM] CWE-833 pam: DoS/user enumeration due to blocking pipe in pam_unix module
pam: DoS/user enumeration due to blocking pipe in pam_unix module
The _unix_run_helper_binary function in the pam_unix module in Linux-PAM (aka pam) before 1.2.1, when unable to directly access passwords, allows local users to enumerate usernames or cause a denial of service (hang) via a large password.
It was discovered that the _unix_run_helper_binary() function of PAM's unix_pam module could write to a blocking pipe, possibly causing the function to become unresponsive. An attacker able to supply large passwords to the unix_pam module could use this flaw to enumerate valid user accounts, or cause a denial of service on the system.
Package: pam (Red Hat Enterprise Linux 5) - Will not fix
Debian
CVE-2015-3238: pam - The _unix_run_helper_binary function in the pam_unix module in Linux-PAM (aka pa...
vendor_debian·2015·CVSS 6.5
CVE-2015-3238 [MEDIUM] CVE-2015-3238: pam - The _unix_run_helper_binary function in the pam_unix module in Linux-PAM (aka pa...
The _unix_run_helper_binary function in the pam_unix module in Linux-PAM (aka pam) before 1.2.1, when unable to directly access passwords, allows local users to enumerate usernames or cause a denial of service (hang) via a large password.
Scope: local
bookworm: resolved (fixed in 1.1.8-3.2)
bullseye: resolved (fixed in 1.1.8-3.2)
forky: resolved (fixed in 1.1.8-3.2)
sid: resolved (fixed in 1.1.8-3.2)
trixie: resolved (fixed in 1.1.8-3.2)
GHSA
GHSA-6r75-hhm5-f689: The _unix_run_helper_binary function in the pam_unix module in Linux-PAM (aka pam) before 1
ghsa_unreviewed·2022-05-14
CVE-2015-3238 [MEDIUM] CWE-200 GHSA-6r75-hhm5-f689: The _unix_run_helper_binary function in the pam_unix module in Linux-PAM (aka pam) before 1
The _unix_run_helper_binary function in the pam_unix module in Linux-PAM (aka pam) before 1.2.1, when unable to directly access passwords, allows local users to enumerate usernames or cause a denial of service (hang) via a large password.
OSV
pam regression
osv·2016-03-16·CVSS 4.3
[MEDIUM] pam regression
pam regression
USN-2935-1 fixed vulnerabilities in PAM. The updates contained a packaging
change that prevented upgrades in certain multiarch environments. This
update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
It was discovered that the PAM pam_userdb module incorrectly used a
case-insensitive method when comparing hashed passwords. A local attacker
could possibly use this issue to make brute force attacks easier. This
issue only affected Ubuntu 12.04 LTS and Ubuntu 14.04 LTS. (CVE-2013-7041)
Sebastian Krahmer discovered that the PAM pam_timestamp module incorrectly
performed filtering. A local attacker could use this issue to create
arbitrary files, or possibly bypass authentication. This issue only
affected Ubuntu 12.04 LTS and Ubuntu 14.04 LT
OSV
pam vulnerabilities
osv·2016-03-16·CVSS 4.3
CVE-2013-7041 [MEDIUM] pam vulnerabilities
pam vulnerabilities
It was discovered that the PAM pam_userdb module incorrectly used a
case-insensitive method when comparing hashed passwords. A local attacker
could possibly use this issue to make brute force attacks easier. This
issue only affected Ubuntu 12.04 LTS and Ubuntu 14.04 LTS. (CVE-2013-7041)
Sebastian Krahmer discovered that the PAM pam_timestamp module incorrectly
performed filtering. A local attacker could use this issue to create
arbitrary files, or possibly bypass authentication. This issue only
affected Ubuntu 12.04 LTS and Ubuntu 14.04 LTS. (CVE-2014-2583)
Sebastien Macke discovered that the PAM pam_unix module incorrectly handled
large passwords. A local attacker could possibly use this issue in certain
environments to enumerate usernames or cause a denial of servi
OSV
CVE-2015-3238: The _unix_run_helper_binary function in the pam_unix module in Linux-PAM (aka pam) before 1
osv·2015-08-24·CVSS 6.5
CVE-2015-3238 [MEDIUM] CVE-2015-3238: The _unix_run_helper_binary function in the pam_unix module in Linux-PAM (aka pam) before 1
The _unix_run_helper_binary function in the pam_unix module in Linux-PAM (aka pam) before 1.2.1, when unable to directly access passwords, allows local users to enumerate usernames or cause a denial of service (hang) via a large password.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-6210 openssh: User enumeration via covert timing channel
bugzilla·2016-07-18·CVSS 6.5
CVE-2016-6210 [MEDIUM] CVE-2016-6210 openssh: User enumeration via covert timing channel
CVE-2016-6210 openssh: User enumeration via covert timing channel
When SSHD tries to authenticate a non-existing user, it will pick up a fake password structure hardcoded in the SSHD source code. On this hard coded password structure the password hash is based on BLOWFISH ($2) algorithm. If real users passwords are hashed using SHA256/SHA512, then sending large passwords (10KB) will result in shorter response time from the server for non-existing users. This allows remote attacker to enumerate existing users on system logging via SSHD.
Published in:
http://seclists.org/fulldisclosure/2016/Jul/51
Discussion:
Created openssh tracking bugs for this issue:
Affects: fedora-all [bug 1357443]
---
OpenSSH in RHEL 6, 7 uses a helper binary "unix_chkpwd" (via the pam_unix module) to verify t
Bugzilla
CVE-2015-3238 pam: DoS/user enumeration due to blocking pipe in pam_unix module
bugzilla·2015-06-05·CVSS 6.5
CVE-2015-3238 [MEDIUM] CVE-2015-3238 pam: DoS/user enumeration due to blocking pipe in pam_unix module
CVE-2015-3238 pam: DoS/user enumeration due to blocking pipe in pam_unix module
From the original report:
"If SELinux is enabled, the _unix_run_helper_binary function in Linux-PAM 1.1.8
and earlier hangs indefinitely when verifying a password of 65536 characters,
which allows attackers to conduct username enumeration and denial of service
attacks.
When supplying a password of 65536 characters or more, the process will block
on the write(2) call at modules/pam_unix/support.c:614 because it tries to
write strlen(passwd)+1 bytes to a blocking pipe and a pipe has a limited
capacity of 65536 bytes on Linux."
Acknowledgements:
Red Hat would like to thank Sebastien Macke of Trustwave SpiderLabs for reporting this issue.
Discussion:
So we (as PAM upstream developers) acknowledge the issue. I
http://lists.fedoraproject.org/pipermail/package-announce/2015-July/161350.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-June/161249.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1640.htmlhttp://www.openwall.com/lists/oss-security/2015/06/25/13http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.htmlhttp://www.securityfocus.com/bid/75428http://www.ubuntu.com/usn/USN-2935-1http://www.ubuntu.com/usn/USN-2935-2http://www.ubuntu.com/usn/USN-2935-3https://bugzilla.redhat.com/show_bug.cgi?id=1228571https://security.gentoo.org/glsa/201605-05https://www.trustwave.com/Resources/Security-Advisories/Advisories/TWSL2015-011/?fid=6551https://www.trustwave.com/Resources/SpiderLabs-Blog/Username-Enumeration-against-OpenSSH-SELinux-with-CVE-2015-3238/http://lists.fedoraproject.org/pipermail/package-announce/2015-July/161350.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-June/161249.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1640.htmlhttp://www.openwall.com/lists/oss-security/2015/06/25/13http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.htmlhttp://www.securityfocus.com/bid/75428http://www.ubuntu.com/usn/USN-2935-1http://www.ubuntu.com/usn/USN-2935-2http://www.ubuntu.com/usn/USN-2935-3https://bugzilla.redhat.com/show_bug.cgi?id=1228571https://security.gentoo.org/glsa/201605-05https://www.trustwave.com/Resources/Security-Advisories/Advisories/TWSL2015-011/?fid=6551https://www.trustwave.com/Resources/SpiderLabs-Blog/Username-Enumeration-against-OpenSSH-SELinux-with-CVE-2015-3238/
2015-08-24
Published