Mark D. Roth PAM_Per_User Authentication Bypass Vulnerability
BID:14813
Info
Mark D. Roth PAM_Per_User Authentication Bypass Vulnerability
| Bugtraq ID: | 14813 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | Yes |
| Published: | Sep 12 2005 12:00AM |
| Updated: | Sep 12 2005 12:00AM |
| Credit: | Vijay Tandeker <[email protected]> reported this issue to the vendor. |
| Vulnerable: |
Mark D. Roth pam_per_user 0.3 Mark D. Roth pam_per_user 0.2 Mark D. Roth pam_per_user 0.1 |
| Not Vulnerable: |
Mark D. Roth pam_per_user 0.4 |
Discussion
Mark D. Roth PAM_Per_User Authentication Bypass Vulnerability
Pam_per_user is prone to an authentication bypass vulnerability. This issue is due to a design error in the module.
Successful exploitation could allow an unauthorized user to bypass authentication, allowing them to gain administrative access to affected computers.
It should be noted that only certain executables that utilize PAM are vulnerable to this issue, due to the method of calling it. The 'login' program is identified as one program that may be exploited, but other programs may also be exploitable in conjunction with this module.
This vulnerability affects pam_per_user versions prior to 0.4.
Pam_per_user is prone to an authentication bypass vulnerability. This issue is due to a design error in the module.
Successful exploitation could allow an unauthorized user to bypass authentication, allowing them to gain administrative access to affected computers.
It should be noted that only certain executables that utilize PAM are vulnerable to this issue, due to the method of calling it. The 'login' program is identified as one program that may be exploited, but other programs may also be exploitable in conjunction with this module.
This vulnerability affects pam_per_user versions prior to 0.4.
Exploit / POC
Mark D. Roth PAM_Per_User Authentication Bypass Vulnerability
An exploit is not required.
An exploit is not required.
Solution / Fix
Mark D. Roth PAM_Per_User Authentication Bypass Vulnerability
Solution:
The vendor has released version 0.4 of pam_per_user to address this issue:
Mark D. Roth pam_per_user 0.1
Mark D. Roth pam_per_user 0.2
Mark D. Roth pam_per_user 0.3
Solution:
The vendor has released version 0.4 of pam_per_user to address this issue:
Mark D. Roth pam_per_user 0.1
-
Mark D. Roth pam_per_user-0.4.tar.gz
ftp://ftp.feep.net/pub/software/PAM/pam_per_user/pam_per_user-0.4.tar. gz
Mark D. Roth pam_per_user 0.2
-
Mark D. Roth pam_per_user-0.4.tar.gz
ftp://ftp.feep.net/pub/software/PAM/pam_per_user/pam_per_user-0.4.tar. gz
Mark D. Roth pam_per_user 0.3
-
Mark D. Roth pam_per_user-0.4.tar.gz
ftp://ftp.feep.net/pub/software/PAM/pam_per_user/pam_per_user-0.4.tar. gz
References
Mark D. Roth PAM_Per_User Authentication Bypass Vulnerability
References:
References:
- pam_per_user Home Page (Mark D. Roth)
- Security Flaw in pam_per_user Module ("Mark D. Roth"
)