Debian Pam vulnerabilities
23 known vulnerabilities affecting debian/pam.
Total CVEs
23
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH2MEDIUM5LOW15
Vulnerabilities
Page 1 of 2
CVE-2009-3232P3CRITICALCVSS 9.3fixed in pam 1.0.1-10 (bookworm)2009
CVE-2009-3232 [CRITICAL] CVE-2009-3232: pam - pam-auth-update for PAM, as used in Ubuntu 8.10 and 9.4, and Debian GNU/Linux, d...
pam-auth-update for PAM, as used in Ubuntu 8.10 and 9.4, and Debian GNU/Linux, does not properly handle an "empty selection" for system authentication modules in certain rare configurations, which causes any attempt to be successful and allows remote attackers to bypass authentication.
Scope: local
bookworm: resolved (fixed in 1.0.1-10)
bullseye: resolved (fixed in 1.
debian
CVE-2024-10963P3LOWCVSS 7.4fixed in pam 1.7.0-5 (forky)2024
CVE-2024-10963 [HIGH] CVE-2024-10963: pam - A flaw was found in pam_access, where certain rules in its configuration file ar...
A flaw was found in pam_access, where certain rules in its configuration file are mistakenly treated as hostnames. This vulnerability allows attackers to trick the system by pretending to be a trusted hostname, gaining unauthorized access. This issue poses a risk for systems that rely on this feature to control who can access certain services or terminals.
Scope: local
debian
CVE-2025-6020P3HIGHCVSS 7.8fixed in pam 1.5.2-6+deb12u2 (bookworm)2025
CVE-2025-6020 [HIGH] CVE-2025-6020: pam - A flaw was found in linux-pam. The module pam_namespace may use access user-cont...
A flaw was found in linux-pam. The module pam_namespace may use access user-controlled paths without proper protection, allowing local users to elevate their privileges to root via multiple symlink attacks and race conditions.
Scope: local
bookworm: resolved (fixed in 1.5.2-6+deb12u2)
bullseye: resolved (fixed in 1.4.0-9+deb11u2)
forky: resolved (fixed in 1.7.0-5)
sid: re
debian
CVE-2014-2583P3LOWCVSS 5.8fixed in pam 1.1.8-3.1 (bookworm)2014
CVE-2014-2583 [MEDIUM] CVE-2014-2583: pam - Multiple directory traversal vulnerabilities in pam_timestamp.c in the pam_times...
Multiple directory traversal vulnerabilities in pam_timestamp.c in the pam_timestamp module for Linux-PAM (aka pam) 1.1.8 allow local users to create arbitrary files or possibly bypass authentication via a .. (dot dot) in the (1) PAM_RUSER value to the get_ruser function or (2) PAM_TTY value to the check_tty function, which is used by the format_timestamp_name function.
debian
CVE-2002-1227P4HIGHCVSS 7.5fixed in pam 0.76-6 (bookworm)2002
CVE-2002-1227 [HIGH] CVE-2002-1227: pam - PAM 0.76 treats a disabled password as if it were an empty (null) password, whic...
PAM 0.76 treats a disabled password as if it were an empty (null) password, which allows local and remote attackers to gain privileges as disabled users.
Scope: local
bookworm: resolved (fixed in 0.76-6)
bullseye: resolved (fixed in 0.76-6)
forky: resolved (fixed in 0.76-6)
sid: resolved (fixed in 0.76-6)
trixie: resolved (fixed in 0.76-6)
debian
CVE-2015-3238P4MEDIUMCVSS 6.5fixed in pam 1.1.8-3.2 (bookworm)2015
CVE-2015-3238 [MEDIUM] CVE-2015-3238: pam - The _unix_run_helper_binary function in the pam_unix module in Linux-PAM (aka pa...
The _unix_run_helper_binary function in the pam_unix module in Linux-PAM (aka pam) before 1.2.1, when unable to directly access passwords, allows local users to enumerate usernames or cause a denial of service (hang) via a large password.
Scope: local
bookworm: resolved (fixed in 1.1.8-3.2)
bullseye: resolved (fixed in 1.1.8-3.2)
forky: resolved (fixed in 1.1.8-3.2)
sid
debian
CVE-2010-3853P4LOWCVSS 6.9fixed in pam 1.1.3-1 (bookworm)2010
CVE-2010-3853 [MEDIUM] CVE-2010-3853: pam - pam_namespace.c in the pam_namespace module in Linux-PAM (aka pam) before 1.1.3 ...
pam_namespace.c in the pam_namespace module in Linux-PAM (aka pam) before 1.1.3 uses the environment of the invoking application or service during execution of the namespace.init script, which might allow local users to gain privileges by running a setuid program that relies on the pam_namespace PAM check, as demonstrated by the sudo program.
Scope: local
bookworm: reso
debian
CVE-2010-4708P4LOWCVSS 7.2fixed in pam 1.1.3-7.1 (bookworm)2010
CVE-2010-4708 [HIGH] CVE-2010-4708: pam - The pam_env module in Linux-PAM (aka pam) 1.1.2 and earlier reads the .pam_envir...
The pam_env module in Linux-PAM (aka pam) 1.1.2 and earlier reads the .pam_environment file in a user's home directory, which might allow local users to run programs with an unintended environment by executing a program that relies on the pam_env PAM check.
Scope: local
bookworm: resolved (fixed in 1.1.3-7.1)
bullseye: resolved (fixed in 1.1.3-7.1)
forky: resolved (fixed
debian
CVE-2024-10041P4MEDIUMCVSS 4.7fixed in pam 1.7.0-2 (forky)2024
CVE-2024-10041 [MEDIUM] CVE-2024-10041: pam - A vulnerability was found in PAM. The secret information is stored in memory, wh...
A vulnerability was found in PAM. The secret information is stored in memory, where the attacker can trigger the victim program to execute by sending characters to its standard input (stdin). As this occurs, the attacker can train the branch predictor to execute an ROP chain speculatively. This flaw could result in leaked passwords, such as those found in /etc/shadow
debian
CVE-2013-7041P4LOWCVSS 4.3fixed in pam 1.1.8-3.1 (bookworm)2013
CVE-2013-7041 [MEDIUM] CVE-2013-7041: pam - The pam_userdb module for Pam uses a case-insensitive method to compare hashed p...
The pam_userdb module for Pam uses a case-insensitive method to compare hashed passwords, which makes it easier for attackers to guess the password via a brute force attack.
Scope: local
bookworm: resolved (fixed in 1.1.8-3.1)
bullseye: resolved (fixed in 1.1.8-3.1)
forky: resolved (fixed in 1.1.8-3.1)
sid: resolved (fixed in 1.1.8-3.1)
trixie: resolved (fixed in 1.1.8-
debian
CVE-2011-3628P4LOWCVSS 6.9fixed in pam 1.1.3-7 (bookworm)2011
CVE-2011-3628 [MEDIUM] CVE-2011-3628: pam - Untrusted search path vulnerability in pam_motd (aka the MOTD module) in libpam-...
Untrusted search path vulnerability in pam_motd (aka the MOTD module) in libpam-modules before 1.1.3-2ubuntu2.1 on Ubuntu 11.10, before 1.1.2-2ubuntu8.4 on Ubuntu 11.04, before 1.1.1-4ubuntu2.4 on Ubuntu 10.10, before 1.1.1-2ubuntu5.4 on Ubuntu 10.04 LTS, and before 0.99.7.1-5ubuntu6.5 on Ubuntu 8.04 LTS, when using certain configurations such as "session optional pam_m
debian
CVE-2009-0887P4LOWCVSS 6.6fixed in pam 1.0.1-10 (bookworm)2009
CVE-2009-0887 [MEDIUM] CVE-2009-0887: pam - Integer signedness error in the _pam_StrTok function in libpam/pam_misc.c in Lin...
Integer signedness error in the _pam_StrTok function in libpam/pam_misc.c in Linux-PAM (aka pam) 1.0.3 and earlier, when a configuration file contains non-ASCII usernames, might allow remote attackers to cause a denial of service, and might allow remote authenticated users to obtain login access with a different user's non-ASCII username, via a login attempt.
Scope: loc
debian
CVE-2011-3148P4MEDIUMCVSS 4.6fixed in pam 1.1.3-5 (bookworm)2011
CVE-2011-3148 [MEDIUM] CVE-2011-3148: pam - Stack-based buffer overflow in the _assemble_line function in modules/pam_env/pa...
Stack-based buffer overflow in the _assemble_line function in modules/pam_env/pam_env.c in Linux-PAM (aka pam) before 1.1.5 allows local users to cause a denial of service (crash) and possibly execute arbitrary code via a long string of white spaces at the beginning of the ~/.pam_environment file.
Scope: local
bookworm: resolved (fixed in 1.1.3-5)
bullseye: resolved (fi
debian
CVE-2024-22365P4MEDIUMCVSS 5.5fixed in pam 1.5.2-6+deb12u2 (bookworm)2024
CVE-2024-22365 [MEDIUM] CVE-2024-22365: pam - linux-pam (aka Linux PAM) before 1.6.0 allows attackers to cause a denial of ser...
linux-pam (aka Linux PAM) before 1.6.0 allows attackers to cause a denial of service (blocked login process) via mkfifo because the openat call (for protect_dir) lacks O_DIRECTORY.
Scope: local
bookworm: resolved (fixed in 1.5.2-6+deb12u2)
bullseye: resolved (fixed in 1.4.0-9+deb11u2)
forky: resolved (fixed in 1.5.3-4)
sid: resolved (fixed in 1.5.3-4)
trixie: resolved
debian
CVE-2010-3435P4LOWCVSS 4.7fixed in pam 1.1.3-1 (bookworm)2010
CVE-2010-3435 [MEDIUM] CVE-2010-3435: pam - The (1) pam_env and (2) pam_mail modules in Linux-PAM (aka pam) before 1.1.2 use...
The (1) pam_env and (2) pam_mail modules in Linux-PAM (aka pam) before 1.1.2 use root privileges during read access to files and directories that belong to arbitrary user accounts, which might allow local users to obtain sensitive information by leveraging this filesystem activity, as demonstrated by a symlink attack on the .pam_environment file in a user's home directo
debian
CVE-2010-4706P4LOWCVSS 4.9fixed in pam 1.1.3-1 (bookworm)2010
CVE-2010-4706 [MEDIUM] CVE-2010-4706: pam - The pam_sm_close_session function in pam_xauth.c in the pam_xauth module in Linu...
The pam_sm_close_session function in pam_xauth.c in the pam_xauth module in Linux-PAM (aka pam) 1.1.2 and earlier does not properly handle a failure to determine a certain target uid, which might allow local users to delete unintended files by executing a program that relies on the pam_xauth PAM check.
Scope: local
bookworm: resolved (fixed in 1.1.3-1)
bullseye: resolve
debian
CVE-2009-0579P4LOWCVSS 4.6fixed in pam 1.0.1-10 (bookworm)2009
CVE-2009-0579 [MEDIUM] CVE-2009-0579: pam - Linux-PAM before 1.0.4 does not enforce the minimum password age (MINDAYS) as sp...
Linux-PAM before 1.0.4 does not enforce the minimum password age (MINDAYS) as specified in /etc/shadow, which allows local users to bypass intended security policy and change their passwords sooner than specified.
Scope: local
bookworm: resolved (fixed in 1.0.1-10)
bullseye: resolved (fixed in 1.0.1-10)
forky: resolved (fixed in 1.0.1-10)
sid: resolved (fixed in 1.0.1-1
debian
CVE-2010-4707P4LOWCVSS 4.9fixed in pam 1.1.3-1 (bookworm)2010
CVE-2010-4707 [MEDIUM] CVE-2010-4707: pam - The check_acl function in pam_xauth.c in the pam_xauth module in Linux-PAM (aka ...
The check_acl function in pam_xauth.c in the pam_xauth module in Linux-PAM (aka pam) 1.1.2 and earlier does not verify that a certain ACL file is a regular file, which might allow local users to cause a denial of service (resource consumption) via a special file.
Scope: local
bookworm: resolved (fixed in 1.1.3-1)
bullseye: resolved (fixed in 1.1.3-1)
forky: resolved (fi
debian
CVE-2010-3430P4MEDIUMCVSS 4.7fixed in pam 1.1.3-1 (bookworm)2010
CVE-2010-3430 [MEDIUM] CVE-2010-3430: pam - The privilege-dropping implementation in the (1) pam_env and (2) pam_mail module...
The privilege-dropping implementation in the (1) pam_env and (2) pam_mail modules in Linux-PAM (aka pam) 1.1.2 does not perform the required setfsgid and setgroups system calls, which might allow local users to obtain sensitive information by leveraging unintended group permissions, as demonstrated by a symlink attack on the .pam_environment file in a user's home direct
debian
CVE-2010-3316P4LOWCVSS 3.3fixed in pam 1.1.2-1 (bookworm)2010
CVE-2010-3316 [LOW] CVE-2010-3316: pam - The run_coprocess function in pam_xauth.c in the pam_xauth module in Linux-PAM (...
The run_coprocess function in pam_xauth.c in the pam_xauth module in Linux-PAM (aka pam) before 1.1.2 does not check the return values of the setuid, setgid, and setgroups system calls, which might allow local users to read arbitrary files by executing a program that relies on the pam_xauth PAM check.
Scope: local
bookworm: resolved (fixed in 1.1.2-1)
bullseye: resolved (f
debian
1 / 2Next →