Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Sebastien Macke

Pesquisador deTrustwave SpiderLabs
#19875de 53,639
13.1CVSS total
Vulnerabilidades · 2
Média
2
PT-2015-6115
6.5
2015-07-05
Linux · Linux-Pam · CVE-2015-3238
**Name of the Vulnerable Software and Affected Versions** Linux-PAM versions prior to 1.2.1 **Description** The issue allows local users to enumerate usernames or cause a denial of service via a large password when the unix run helper binary function in the pam unix module is unable to directly access passwords. **Recommendations** For versions prior to 1.2.1, update to version 1.2.1 or later to resolve the issue.
PT-2014-1808
6.6
2014-03-10
Todd Miller · Sudo · CVE-2014-0106
**Name of the Vulnerable Software and Affected Versions** sudo versions prior to 1.8.5 sudo-debuginfo-1.7.2p1 sudo-1.7.2p1 **Description** The issue allows local users with sudo permissions to bypass intended command restrictions via a crafted environment variable, potentially leading to a breach of confidentiality, integrity, and availability of protected information. This can be exploited locally by an authenticated attacker. **Recommendations** For versions prior to 1.8.5, update to version 1.8.5 or later to resolve the issue. For sudo-debuginfo-1.7.2p1 and sudo-1.7.2p1, update to a version that includes the fix for this issue, as these specific versions are affected. As a temporary workaround, consider enabling the env reset option to minimize the risk of exploitation.