PT-2015-7849 · Linux Pam+2 · Pam Radius+2

Laura Pardo

·

Publicado

2015-12-31

·

Atualizado

2021-07-11

·

CVE-2015-9542

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions pam radius version 1.4.0
Description The issue arises from the add password function in pam radius auth.c, which fails to correctly check the length of the input password. This oversight makes it vulnerable to a stack-based buffer overflow during the memcpy() operation. An attacker could exploit this by sending a crafted password to an application that loads the pam radius library, potentially crashing the application. Depending on various factors such as the application, C library, compiler, and other environmental elements, arbitrary code execution might be feasible.
Recommendations For pam radius version 1.4.0, consider updating to a newer version that addresses this issue, as the current version is susceptible to a stack-based buffer overflow. As a temporary workaround, consider restricting the use of the add password function in pam radius auth.c to minimize the risk of exploitation. Additionally, be cautious when handling input passwords to prevent potential crashes or arbitrary code execution.

Correção

Memory Corruption

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2015-9542
DLA-2116-1
DLA-2304-1
OPENSUSE-SU-2021:0870-1
OPENSUSE-SU-2021:1896-1
OPENSUSE-SU-2021_0870-1
OPENSUSE-SU-2021_1896-1
OPENSUSE-SU-2024:11144-1
SUSE-SU-2020:1117-1
SUSE-SU-2020_1117-1
SUSE-SU-2021:1896-1
SUSE-SU-2021_1896-1
USN-4290-1
USN-4290-2

Produtos afetados

Suse
Ubuntu
Pam Radius