|
Linux PAM Authentication Bypass Vulnerability
Debian has reported a vulnerability in Linux PAM that may result in remote intruders gaining unauthorized access to systems. According to the report, vulnerable versions of PAM treat "locked" passwords (value of "*" in /etc/passwd) as no password. Consequently, remote users may login as blocked users without supplying any credentials. Provided that a functional shell is designated for the user, remote attackers may exploit this vulnerability to gain local access to target systems. |
|
|
Privacy Statement |