PT-2005-3795 · Linux Pam · Pam Per User

Vijay Tandeker

·

Publicado

2005-09-16

·

Atualizado

2016-10-18

·

CVE-2005-2949

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions pam per user versions prior to 0.4
Description The issue allows remote attackers or local users to login as other users by using certain applications that allow the username to be changed during authentication. This can be achieved with applications such as /bin/login.
Recommendations For versions prior to 0.4, update to version 0.4 or later to resolve the issue. As a temporary workaround, consider restricting the use of applications that allow username changes during authentication, such as /bin/login, until the update is applied.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2005-2949

Produtos afetados

Pam Per User