PAM Unix_Chkpwd Unauthorized Access Vulnerability
BID:15217
Info
PAM Unix_Chkpwd Unauthorized Access Vulnerability
| Bugtraq ID: | 15217 |
| Class: | Design Error |
| CVE: |
CVE-2005-2977 |
| Remote: | No |
| Local: | Yes |
| Published: | Oct 26 2005 12:00AM |
| Updated: | Oct 26 2005 12:00AM |
| Credit: | This issue was disclosed in the referenced RedHat Fedora advisory. |
| Vulnerable: |
Redhat Fedora Core4 Redhat Fedora Core3 Redhat Enterprise Linux WS 4 Redhat Enterprise Linux ES 4 Redhat Enterprise Linux AS 4 Redhat Desktop 4.0 Linux-PAM Linux-PAM 0.77 Gentoo Linux |
| Not Vulnerable: | |
Discussion
PAM Unix_Chkpwd Unauthorized Access Vulnerability
The PAM unix_chkpwd command is prone to an unauthorized access vulnerability.
A local attacker can exploit this vulnerability to perform brute force attacks to obtain the valid passwords of other local users.
The PAM unix_chkpwd command is prone to an unauthorized access vulnerability.
A local attacker can exploit this vulnerability to perform brute force attacks to obtain the valid passwords of other local users.
Exploit / POC
PAM Unix_Chkpwd Unauthorized Access Vulnerability
No exploit is required.
No exploit is required.
Solution / Fix
PAM Unix_Chkpwd Unauthorized Access Vulnerability
Solution:
RedHat Fedora has released security advisory FEDORA-2005-1030 addressing this issue for Fedora Core 3. Users are advised to see the referenced advisory for details on obtaining and applying the appropriate updates.
RedHat has released security advisory RHSA-2005:805-6 addressing this issue for their Desktop and Enterprise 4 platforms. Please see the referenced Web advisory for further information.
RedHat Fedora has released security advisory FEDORA-2005-1031 addressing this issue for Fedora Core 4. Users are advised to see the referenced advisory for details on obtaining and applying the appropriate updates.
Gentoo has released advisory GLSA 200510-22 and fixes to address this issue. To obtain fixes, users should execute the following:
emerge --sync
emerge --ask --oneshot --verbose ">=sys-libs/pam-0.78-r3"
--
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
RedHat Fedora has released security advisory FEDORA-2005-1030 addressing this issue for Fedora Core 3. Users are advised to see the referenced advisory for details on obtaining and applying the appropriate updates.
RedHat has released security advisory RHSA-2005:805-6 addressing this issue for their Desktop and Enterprise 4 platforms. Please see the referenced Web advisory for further information.
RedHat Fedora has released security advisory FEDORA-2005-1031 addressing this issue for Fedora Core 4. Users are advised to see the referenced advisory for details on obtaining and applying the appropriate updates.
Gentoo has released advisory GLSA 200510-22 and fixes to address this issue. To obtain fixes, users should execute the following:
emerge --sync
emerge --ask --oneshot --verbose ">=sys-libs/pam-0.78-r3"
--
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
PAM Unix_Chkpwd Unauthorized Access Vulnerability
References:
References: