7.5
CVSSv2

CVE-2006-0056

Published: 13/02/2006 Updated: 08/03/2011
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Double free vulnerability in the authentication and authentication token alteration code in PAM-MySQL 0.6.x prior to 0.6.2 and 0.7.x prior to 0.7pre3 allows remote malicious users to cause a denial of service (application crash) and possibly execute arbitrary code via crafted passwords, which lead to a double free of a pointer that was created by the pam_get_item function. NOTE: this issue only occurs in certain configurations in which there are multiple PAM modules, PAM-MySQL is not evaluated first, and there are no requisite modules before PAM-MySQL.

Vulnerable Product Search on Vulmon Subscribe to Product

pam-mysql pam-mysql 0.1

pam-mysql pam-mysql 0.2

pam-mysql pam-mysql 0.7_pre2

pam-mysql pam-mysql 0.6

pam-mysql pam-mysql 0.7_pre1

pam-mysql pam-mysql 0.3

pam-mysql pam-mysql 0.4

pam-mysql pam-mysql 0.4.7

pam-mysql pam-mysql 0.5

Vendor Advisories

Debian Bug report logs - #353589 CVE-2005-4713 and CVE-2006-0056: remote vulnerabilities Package: libpam-mysql; Maintainer for libpam-mysql is Ferenc Wágner <wferi@debianorg>; Source for libpam-mysql is src:pam-mysql (PTS, buildd, popcon) Reported by: Micah Anderson <micah@debianorg> Date: Sun, 19 Feb 2006 19:03: ...