cbcvebase.

Debian Pam vulnerabilities

23 known vulnerabilities affecting debian/pam.

Total CVEs
23
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH2MEDIUM5LOW15

Vulnerabilities

Page 2 of 2
CVE-2011-3149P4LOWCVSS 2.1fixed in pam 1.1.3-5 (bookworm)2011
CVE-2011-3149 [LOW] CVE-2011-3149: pam - The _expand_arg function in the pam_env module (modules/pam_env/pam_env.c) in Li... The _expand_arg function in the pam_env module (modules/pam_env/pam_env.c) in Linux-PAM (aka pam) before 1.1.5 does not properly handle when environment variable expansion can overflow, which allows local users to cause a denial of service (CPU consumption). Scope: local bookworm: resolved (fixed in 1.1.3-5) bullseye: resolved (fixed in 1.1.3-5) forky: resolved (fixed in 1
debian
CVE-2005-2977P4LOWCVSS 2.1fixed in pam 0.99.7.1-2 (bookworm)2005
CVE-2005-2977 [LOW] CVE-2005-2977: pam - The SELinux version of PAM before 0.78 r3 allows local users to perform brute fo... The SELinux version of PAM before 0.78 r3 allows local users to perform brute force password guessing attacks via unix_chkpwd, which does not log failed guesses or delay its responses. Scope: local bookworm: resolved (fixed in 0.99.7.1-2) bullseye: resolved (fixed in 0.99.7.1-2) forky: resolved (fixed in 0.99.7.1-2) sid: resolved (fixed in 0.99.7.1-2) trixie: resolved (fix
debian
CVE-2010-3431P4LOWCVSS 1.9fixed in pam 1.1.3-1 (bookworm)2010
CVE-2010-3431 [LOW] CVE-2010-3431: pam - The privilege-dropping implementation in the (1) pam_env and (2) pam_mail module... The privilege-dropping implementation in the (1) pam_env and (2) pam_mail modules in Linux-PAM (aka pam) 1.1.2 does not check the return value of the setfsuid system call, which might allow local users to obtain sensitive information by leveraging an unintended uid, as demonstrated by a symlink attack on the .pam_environment file in a user's home directory. NOTE: this vuln
debian
Debian Pam vulnerabilities | cvebase