6.6
CVSSv2

CVE-2009-0887

Published: 12/03/2009 Updated: 07/11/2023
CVSS v2 Base Score: 6.6 | Impact Score: 10 | Exploitability Score: 2.7
VMScore: 587
Vector: AV:L/AC:M/Au:S/C:C/I:C/A:C

Vulnerability Summary

Integer signedness error in the _pam_StrTok function in libpam/pam_misc.c in Linux-PAM (aka pam) 1.0.3 and previous versions, when a configuration file contains non-ASCII usernames, might allow remote malicious users to cause a denial of service, and might allow remote authenticated users to obtain login access with a different user's non-ASCII username, via a login attempt.

Vulnerable Product Search on Vulmon Subscribe to Product

linux-pam linux-pam 0.99.1.0

linux-pam linux-pam 0.99.2.0

linux-pam linux-pam 0.99.2.1

linux-pam linux-pam 0.99.3.0

linux-pam linux-pam 0.99.4.0

linux-pam linux-pam 0.99.5.0

linux-pam linux-pam 0.99.6.0

linux-pam linux-pam 0.99.6.1

linux-pam linux-pam 0.99.6.2

linux-pam linux-pam 0.99.6.3

linux-pam linux-pam 0.99.7.0

linux-pam linux-pam 0.99.7.1

linux-pam linux-pam 0.99.8.0

linux-pam linux-pam 0.99.8.1

linux-pam linux-pam 0.99.9.0

linux-pam linux-pam 0.99.10.0

linux-pam linux-pam 1.0.0

linux-pam linux-pam 1.0.1

linux-pam linux-pam 1.0.2

linux-pam linux-pam

Vendor Advisories

An attacker could cause PAM to read or delete arbitrary files or cause it to crash ...
The USN-1140-1 PAM update caused cron to stop working ...
Debian Bug report logs - #514437 chage -m / passwd -n (--mindays) have no effect (Lenny) Package: libpam-modules; Maintainer for libpam-modules is Steve Langasek <vorlon@debianorg>; Source for libpam-modules is src:pam (PTS, buildd, popcon) Reported by: Stefan Lienesch <lieneschgag@ewetelnet> Date: Sat, 7 Feb 200 ...
Debian Bug report logs - #519927 pam-auth-update does not prohibit selecting an empty set of modules Package: pam; Maintainer for pam is Steve Langasek <vorlon@debianorg>; Reported by: Russell Senior <seniorr@aracnetcom> Date: Mon, 16 Mar 2009 10:48:34 UTC Severity: serious Tags: security Merged with 521038, 528794 ...
Debian Bug report logs - #520115 pam: CVE-2009-0887 integer signedness error could lead to DoS or authentication bypass Package: pam; Maintainer for pam is Steve Langasek <vorlon@debianorg>; Reported by: Nico Golde <nion@debianorg> Date: Tue, 17 Mar 2009 14:15:01 UTC Severity: important Tags: fixed-upstream, patch, ...