← Back

CVE-2009-0887

nvd nist
Published: Mar 12, 2009Modified: Apr 23, 2026

JSON object

Loading...
6.6
Vector
AV:L/AC:M/Au:S/C:C/I:C/A:C
Exploitability: 2.7 / Impact: 10.0
Source: NVD

Description

Integer signedness error in the _pam_StrTok function in libpam/pam_misc.c in Linux-PAM (aka pam) 1.0.3 and earlier, when a configuration file contains non-ASCII usernames, might allow remote attackers to cause a denial of service, and might allow remote authenticated users to obtain login access with a different user's non-ASCII username, via a login attempt.

Affected (20)

Products: Linux Pam: Linux Pam
1 product
Linux Pam
Configuration A
20 vulnerable
Vulnerable SoftwareAffected Versions
Linux Pam
Up to 1.0.3
Version 0.99.1.0
Version 0.99.10.0
Version 0.99.2.0
Version 0.99.2.1
Version 0.99.3.0
Version 0.99.4.0
Version 0.99.5.0
Version 0.99.6.0
Version 0.99.6.1
Version 0.99.6.2
Version 0.99.6.3
Version 0.99.7.0
Version 0.99.7.1
Version 0.99.8.0
Version 0.99.8.1
Version 0.99.9.0
Version 1.0.0
Version 1.0.1
Version 1.0.2

Related CWEs

References (18)

Source: cve@mitre.org
Patch
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Patch
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.