Back to search
CVE-2013-0191
Published: Jun 3, 2014
Modified: Aug 6, 2024
PUBLISHED
Description
libpam-pgsql (aka pam_pgsql) 0.7 does not properly handle a NULL value returned by the password search query, which allows remote attackers to bypass authentication via a crafted password.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
SUSE-SU-2016:1996
vendor-advisory
x_refsource_SUSE
[oss-security] 20130115 pam-pgsql NULL password handling issue
mailing-list
x_refsource_MLIST
57440
vdb-entry
x_refsource_BID
http://sourceforge.net/p/pam-pgsql/bugs/13/
x_refsource_MISC
SUSE-SU-2016:2089
vendor-advisory
x_refsource_SUSE
[oss-security] 20130116 Re: pam-pgsql NULL password handling issue
mailing-list
x_refsource_MLIST
libpampgsql-password-sec-bypass(81363)
vdb-entry
x_refsource_XF
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now