CVE-2009-0887
NONE EPSS 77.5%
Published Mar 12, 200917y ago · Modified Jun 16, 20262w ago
Published Mar 12, 2009 17y ago
Last Modified Jun 16, 2026 2w ago
Description
Integer signedness error in the _pam_StrTok function in libpam/pam_misc.c in Linux-PAM (aka pam) 1.0.3 and earlier, when a configuration file contains non-ASCII usernames, might allow remote attackers to cause a denial of service, and might allow remote authenticated users to obtain login access with a different user's non-ASCII username, via a login attempt.
Threat Intelligence
EPSS Exploit Probability
77.5% percentile
Exploit & Patch Status
Public Exploit Known
Patch Available
Weaknesses 1
CWE-189
Affected Products 20
| Vendor | Product | Version | Range |
|---|---|---|---|
| linux-pam | linux-pam | * | ≤1.0.3 |
| linux-pam | linux-pam | 0.99.1.0 | any |
| linux-pam | linux-pam | 0.99.2.0 | any |
| linux-pam | linux-pam | 0.99.2.1 | any |
| linux-pam | linux-pam | 0.99.3.0 | any |
| linux-pam | linux-pam | 0.99.4.0 | any |
| linux-pam | linux-pam | 0.99.5.0 | any |
| linux-pam | linux-pam | 0.99.6.0 | any |
| linux-pam | linux-pam | 0.99.6.1 | any |
| linux-pam | linux-pam | 0.99.6.2 | any |
| linux-pam | linux-pam | 0.99.6.3 | any |
| linux-pam | linux-pam | 0.99.7.0 | any |
| linux-pam | linux-pam | 0.99.7.1 | any |
| linux-pam | linux-pam | 0.99.8.0 | any |
| linux-pam | linux-pam | 0.99.8.1 | any |
| linux-pam | linux-pam | 0.99.9.0 | any |
| linux-pam | linux-pam | 0.99.10.0 | any |
| linux-pam | linux-pam | 1.0.0 | any |
| linux-pam | linux-pam | 1.0.1 | any |
| linux-pam | linux-pam | 1.0.2 | any |
References 9
- openwall.com http://openwall.com/lists/oss-security/2009/03/05/1
- pam.cvs.sourceforge.net http://pam.cvs.sourceforge.net/viewvc/pam/Linux-PAM/libpam/pam_misc.c?r1=1.9&%3Br2=1.10&%3Bview=patch
- pam.cvs.sourceforge.net http://pam.cvs.sourceforge.net/viewvc/pam/Linux-PAM/libpam/pam_misc.c?view=log
- secunia.com http://secunia.com/advisories/34733
- mandriva.com http://www.mandriva.com/security/advisories?name=MDVSA-2009:077
- securityfocus.com http://www.securityfocus.com/bid/34010
- exchange.xforce.ibmcloud.com https://exchange.xforce.ibmcloud.com/vulnerabilities/49110
- redhat.com https://www.redhat.com/archives/fedora-package-announce/2009-April/msg00398.html
- redhat.com https://www.redhat.com/archives/fedora-package-announce/2009-April/msg00420.html
Remediation
- securityfocus.com http://www.securityfocus.com/bid/34010