CVE-2009-0887

NONE EPSS 77.5%
Published Mar 12, 200917y ago · Modified Jun 16, 20262w ago
Find Similar
Published Mar 12, 2009 17y ago
Last Modified Jun 16, 2026 2w ago

Description

Integer signedness error in the _pam_StrTok function in libpam/pam_misc.c in Linux-PAM (aka pam) 1.0.3 and earlier, when a configuration file contains non-ASCII usernames, might allow remote attackers to cause a denial of service, and might allow remote authenticated users to obtain login access with a different user's non-ASCII username, via a login attempt.

Threat Intelligence

EPSS Exploit Probability
77.5% percentile
Exploit & Patch Status
Public Exploit Known
Patch Available

Weaknesses 1

CWE-189

Affected Products 20

VendorProductVersionRange
linux-pamlinux-pam* ≤1.0.3
linux-pamlinux-pam0.99.1.0any
linux-pamlinux-pam0.99.2.0any
linux-pamlinux-pam0.99.2.1any
linux-pamlinux-pam0.99.3.0any
linux-pamlinux-pam0.99.4.0any
linux-pamlinux-pam0.99.5.0any
linux-pamlinux-pam0.99.6.0any
linux-pamlinux-pam0.99.6.1any
linux-pamlinux-pam0.99.6.2any
linux-pamlinux-pam0.99.6.3any
linux-pamlinux-pam0.99.7.0any
linux-pamlinux-pam0.99.7.1any
linux-pamlinux-pam0.99.8.0any
linux-pamlinux-pam0.99.8.1any
linux-pamlinux-pam0.99.9.0any
linux-pamlinux-pam0.99.10.0any
linux-pamlinux-pam1.0.0any
linux-pamlinux-pam1.0.1any
linux-pamlinux-pam1.0.2any

References 9

  • openwall.com http://openwall.com/lists/oss-security/2009/03/05/1
    Exploit
  • pam.cvs.sourceforge.net http://pam.cvs.sourceforge.net/viewvc/pam/Linux-PAM/libpam/pam_misc.c?r1=1.9&amp%3Br2=1.10&amp%3Bview=patch
  • pam.cvs.sourceforge.net http://pam.cvs.sourceforge.net/viewvc/pam/Linux-PAM/libpam/pam_misc.c?view=log
  • secunia.com http://secunia.com/advisories/34733
  • mandriva.com http://www.mandriva.com/security/advisories?name=MDVSA-2009:077
  • securityfocus.com http://www.securityfocus.com/bid/34010
    Patch
  • exchange.xforce.ibmcloud.com https://exchange.xforce.ibmcloud.com/vulnerabilities/49110
  • redhat.com https://www.redhat.com/archives/fedora-package-announce/2009-April/msg00398.html
  • redhat.com https://www.redhat.com/archives/fedora-package-announce/2009-April/msg00420.html

Remediation