7.5
CVSSv2

CVE-2002-1227

Published: 28/10/2002 Updated: 05/09/2008
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

PAM 0.76 treats a disabled password as if it were an empty (null) password, which allows local and remote malicious users to gain privileges as disabled users.

Vulnerable Product Search on Vulmon Subscribe to Product

pam pam 0.76

Vendor Advisories

A serious security violation in PAM was discovered Disabled passwords (ie those with '*' in the password file) were classified as empty password and access to such accounts is granted through the regular login procedure (getty, telnet, ssh) This works for all such accounts whose shell field in the password file does not refer to /bin/false Onl ...