Back to search
CVE-2007-0003
Published: Jan 23, 2007
Modified: Aug 7, 2024
PUBLISHED
Description
pam_unix.so in Linux-PAM 0.99.7.0 allows context-dependent attackers to log into accounts whose password hash, as stored in /etc/passwd or /etc/shadow, has only two characters.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
32017
vdb-entry
x_refsource_OSVDB
linuxpam-pamunix-security-bypass(31739)
vdb-entry
x_refsource_XF
SUSE-SR:2007:003
vendor-advisory
x_refsource_SUSE
[pam-list] 20070123 Linux-PAM 0.99.7.1 released
mailing-list
x_refsource_MLIST
[fedora-devel-list] 20070122 Re: rawhide report: 20070120 changes
mailing-list
x_refsource_MLIST
ADV-2007-0323
vdb-entry
x_refsource_VUPEN
[fedora-devel-list] 20070122 Re: rawhide report: 20070120 changes
mailing-list
x_refsource_MLIST
23858
third-party-advisory
x_refsource_SECUNIA
22204
vdb-entry
x_refsource_BID
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now