PT-2011-5205 · Linux Pam+4 · Pam+5

Kees

+1

·

Published

1970-01-01

·

Updated

2024-06-15

·

CVE-2011-3148

CVSS v2.0

4.6

Medium

VectorAV:L/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions openSUSE pam versions prior to 1.1.5 SUSE Linux Enterprise pam versions prior to 1.1.5 Debian GNU/Linux pam versions prior to 1.1.5 openSUSE pam-32bit versions prior to 1.1.5 SUSE Linux Enterprise pam-32bit versions prior to 1.1.5 openSUSE pam-devel versions prior to 1.1.5 SUSE Linux Enterprise pam-devel versions prior to 1.1.5 SUSE Linux Enterprise pam-devel-32bit versions prior to 1.1.5 openSUSE pam-devel-32bit versions prior to 1.1.5 SUSE Linux Enterprise pam-devel-64bit versions prior to 1.1.5
Description The issue is related to multiple vulnerabilities in the pam package of various Linux operating systems, including openSUSE, SUSE Linux Enterprise, and Debian GNU/Linux. These vulnerabilities can be exploited locally, potentially leading to a violation of confidentiality, integrity, and availability of protected information. A specific vulnerability is a stack-based buffer overflow in the assemble line function in modules/pam env/pam env.c in Linux-PAM before version 1.1.5, which allows local users to cause a denial of service and possibly execute arbitrary code via a long string of white spaces at the beginning of the ~/.pam environment file.
Recommendations For openSUSE pam versions prior to 1.1.5, update to version 1.1.5 or later. For SUSE Linux Enterprise pam versions prior to 1.1.5, update to version 1.1.5 or later. For Debian GNU/Linux pam versions prior to 1.1.5, update to version 1.1.5 or later. For openSUSE pam-32bit versions prior to 1.1.5, update to version 1.1.5 or later. For SUSE Linux Enterprise pam-32bit versions prior to 1.1.5, update to version 1.1.5 or later. For openSUSE pam-devel versions prior to 1.1.5, update to version 1.1.5 or later. For SUSE Linux Enterprise pam-devel versions prior to 1.1.5, update to version 1.1.5 or later. For SUSE Linux Enterprise pam-devel-32bit versions prior to 1.1.5, update to version 1.1.5 or later. For openSUSE pam-devel-32bit versions prior to 1.1.5, update to version 1.1.5 or later. For SUSE Linux Enterprise pam-devel-64bit versions prior to 1.1.5, update to version 1.1.5 or later. As a temporary workaround, consider restricting access to the ~/.pam environment file to minimize the risk of exploitation.

Exploit

Fix

DoS

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-03055
BDU:2015-04370
BDU:2015-04371
BDU:2015-04372
BDU:2015-04373
BDU:2015-04374
BDU:2015-04633
BDU:2015-04634
BDU:2015-05381
BDU:2015-05382
BDU:2015-05383
BDU:2015-05384
BDU:2015-05385
CESA-2013_0521
CVE-2011-3148
DSA-2326-1
OPENSUSE-SU-2024:10405-1
RHSA-2013:0521
RHSA-2013_0521

Affected Products

Centos
Debian
Red Hat
Suse Linux Enterprise
Opensuse
Pam