Double free vulnerability in the authentication and authentication token alteration code in PAM-MySQL 0.6.x prior to 0.6.2 and 0.7.x prior to 0.7pre3 allows remote malicious users to cause a denial of service (application crash) and possibly execute arbitrary code via crafted passwords, which lead to a double free of a pointer that was created by the pam_get_item function. NOTE: this issue only occurs in certain configurations in which there are multiple PAM modules, PAM-MySQL is not evaluated first, and there are no requisite modules before PAM-MySQL.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
pam-mysql pam-mysql 0.1 |
||
pam-mysql pam-mysql 0.2 |
||
pam-mysql pam-mysql 0.7_pre2 |
||
pam-mysql pam-mysql 0.6 |
||
pam-mysql pam-mysql 0.7_pre1 |
||
pam-mysql pam-mysql 0.3 |
||
pam-mysql pam-mysql 0.4 |
||
pam-mysql pam-mysql 0.4.7 |
||
pam-mysql pam-mysql 0.5 |