PT-2015-6115 · Linux+5 · Linux-Pam+5

Sebastien Macke

·

Published

2015-07-05

·

Updated

2024-06-15

·

CVE-2015-3238

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L
Name of the Vulnerable Software and Affected Versions Linux-PAM versions prior to 1.2.1
Description The issue allows local users to enumerate usernames or cause a denial of service via a large password when the unix run helper binary function in the pam unix module is unable to directly access passwords.
Recommendations For versions prior to 1.2.1, update to version 1.2.1 or later to resolve the issue.

Exploit

Fix

DoS

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2016-1613
CESA-2015_1640
CVE-2015-3238
ELSA-2015-1640
MGASA-2015-0266
OPENSUSE-SU-2024:10405-1
RHSA-2015:1640
RHSA-2015_1640
SUSE-SU-2016:1645-1
SUSE-SU-2017:1398-1
SUSE-SU-2017:2699-1
SUSE-SU-2017:2700-1
SUSE-SU-2017_1398-1
USN-2935-1
USN-2935-2

Affected Products

Alt Linux
Centos
Linux-Pam
Red Hat
Suse
Ubuntu