Linux PAM Authentication Bypass Vulnerability
BID:5994
Info
Linux PAM Authentication Bypass Vulnerability
| Bugtraq ID: | 5994 |
| Class: | Access Validation Error |
| CVE: |
CVE-2002-1227 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 17 2002 12:00AM |
| Updated: | Jul 11 2009 06:06PM |
| Credit: | Attributed to Paul Aurich and Samuele Giovanni Tonon. |
| Vulnerable: |
Andrew G. Morgan Linux PAM 0.76 |
| Not Vulnerable: | |
Discussion
Linux PAM Authentication Bypass Vulnerability
Debian has reported a vulnerability in Linux PAM that may result in remote intruders gaining unauthorized access to systems. According to the report, vulnerable versions of PAM treat "locked" passwords (value of "*" in /etc/passwd) as no password. Consequently, remote users may login as blocked users without supplying any credentials. Provided that a functional shell is designated for the user, remote attackers may exploit this vulnerability to gain local access to target systems.
Debian has reported a vulnerability in Linux PAM that may result in remote intruders gaining unauthorized access to systems. According to the report, vulnerable versions of PAM treat "locked" passwords (value of "*" in /etc/passwd) as no password. Consequently, remote users may login as blocked users without supplying any credentials. Provided that a functional shell is designated for the user, remote attackers may exploit this vulnerability to gain local access to target systems.