Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Linux PAM Authentication Bypass Vulnerability

Debian has reported a vulnerability in Linux PAM that may result in remote intruders gaining unauthorized access to systems. According to the report, vulnerable versions of PAM treat "locked" passwords (value of "*" in /etc/passwd) as no password. Consequently, remote users may login as blocked users without supplying any credentials. Provided that a functional shell is designated for the user, remote attackers may exploit this vulnerability to gain local access to target systems.







 

Privacy Statement
Copyright 2008, SecurityFocus