libpam-pgsql 'pam_pgsql.c' Authentication Bypass Vulnerability
BID:29360
Info
libpam-pgsql 'pam_pgsql.c' Authentication Bypass Vulnerability
| Bugtraq ID: | 29360 |
| Class: | Access Validation Error |
| CVE: |
CVE-2008-2516 |
| Remote: | No |
| Local: | Yes |
| Published: | May 19 2008 12:00AM |
| Updated: | May 07 2015 05:28PM |
| Credit: | Julian Mehnle |
| Vulnerable: |
libpam-pgsql libpam-pgsql 0.6.3 |
| Not Vulnerable: |
libpam-pgsql libpam-pgsql 0.6.4 |
Discussion
libpam-pgsql 'pam_pgsql.c' Authentication Bypass Vulnerability
The 'libpam-pgsql' module is prone to an authentication-bypass vulnerability that could let an attacker bypass authentication in applications that use this module for authenticating users.
The issue affects libpam-pgsql 0.6.3 and prior versions.
The 'libpam-pgsql' module is prone to an authentication-bypass vulnerability that could let an attacker bypass authentication in applications that use this module for authenticating users.
The issue affects libpam-pgsql 0.6.3 and prior versions.
Exploit / POC
libpam-pgsql 'pam_pgsql.c' Authentication Bypass Vulnerability
The attacker may exploit the vulnerability by sending a 'SIGINT' signal during the authentication process.
The attacker may exploit the vulnerability by sending a 'SIGINT' signal during the authentication process.
Solution / Fix
libpam-pgsql 'pam_pgsql.c' Authentication Bypass Vulnerability
Solution:
The vendor has released an update. Please see the references for more information.
Solution:
The vendor has released an update. Please see the references for more information.
References
libpam-pgsql 'pam_pgsql.c' Authentication Bypass Vulnerability
References:
References:
- libpam-pgsql Homepage (libpam-pgsql)
- libpam-pgsql:
while in authentication phase induces success, may circum (Julian Mehnle) - libpam-pgsql Changelog 0.6.4 (libpam-pgsql)