Vulnerability Database

289,697

Total vulnerabilities in the database

CVE-2009-0887

Integer signedness error in the _pam_StrTok function in libpam/pam_misc.c in Linux-PAM (aka pam) 1.0.3 and earlier, when a configuration file contains non-ASCII usernames, might allow remote attackers to cause a denial of service, and might allow remote authenticated users to obtain login access with a different user's non-ASCII username, via a login attempt.

  • Published: Mar 12, 2009
  • Updated: Apr 13, 2023
  • CVE: CVE-2009-0887
  • Severity: Medium
  • Exploit:

CVSS v2:

  • Severity: Medium
  • Score: 6.6
  • AV:L/AC:M/Au:S/C:C/I:C/A:C

CWEs:

Software From Fixed in
linux-pam / linux-pam 0.99.1.0 0.99.1.0.x
linux-pam / linux-pam 0.99.2.0 0.99.2.0.x
linux-pam / linux-pam 0.99.2.1 0.99.2.1.x
linux-pam / linux-pam 0.99.3.0 0.99.3.0.x
linux-pam / linux-pam 0.99.4.0 0.99.4.0.x
linux-pam / linux-pam 0.99.5.0 0.99.5.0.x
linux-pam / linux-pam 0.99.6.0 0.99.6.0.x
linux-pam / linux-pam 0.99.6.1 0.99.6.1.x
linux-pam / linux-pam 0.99.6.2 0.99.6.2.x
linux-pam / linux-pam 0.99.6.3 0.99.6.3.x
linux-pam / linux-pam 0.99.7.0 0.99.7.0.x
linux-pam / linux-pam 0.99.7.1 0.99.7.1.x
linux-pam / linux-pam 0.99.8.0 0.99.8.0.x
linux-pam / linux-pam 0.99.8.1 0.99.8.1.x
linux-pam / linux-pam 0.99.9.0 0.99.9.0.x
linux-pam / linux-pam 0.99.10.0 0.99.10.0.x
linux-pam / linux-pam 1.0.0 1.0.0.x
linux-pam / linux-pam 1.0.1 1.0.1.x
linux-pam / linux-pam 1.0.2 1.0.2.x
linux-pam / linux-pam - 1.0.3.x