10
CVSSv2

CVE-2016-4422

Published: 06/05/2016 Updated: 05/04/2021
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 890
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

The pam_sm_authenticate function in pam_sshauth.c in libpam-sshauth might allow context-dependent malicious users to bypass authentication or gain privileges via a system user account.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

libpam-sshauth project libpam-sshauth -

debian debian linux 8.0

Vendor Advisories

It was discovered that libpam-sshauth, a PAM module to authenticate using an SSH server, does not correctly handle system users In certain configurations an attacker can take advantage of this flaw to gain root privileges For the stable distribution (jessie), this problem has been fixed in version 031-1+deb8u1 For the testing distribution (str ...