HomeLinux-PamCVE-2009-0887

CVE-2009-0887

UNKNOWN
6.6CVSS
Published: 2009-03-12
Updated: 2025-04-09
AI Analysis

Description

Integer signedness error in the _pam_StrTok function in libpam/pam_misc.c in Linux-PAM (aka pam) 1.0.3 and earlier, when a configuration file contains non-ASCII usernames, might allow remote attackers to cause a denial of service, and might allow remote authenticated users to obtain login access with a different user's non-ASCII username, via a login attempt.

CVSS Metrics

Vector
AV:L/AC:M/Au:S/C:C/I:C/A:C
Access Vector
local
Access Cmplx
medium
Auth
single
Confidentiality
complete
Integrity
complete
Availability
complete
Weaknesses
CWE-189

Metadata

Primary Vendor
LINUX-PAM
Published
3/12/2009
Last Modified
4/9/2025
Source
NIST NVD
Note: Verify all details with official vendor sources before applying patches.

Affected Products

linux-pam : linux-pamlinux-pam : linux-pamlinux-pam : linux-pamlinux-pam : linux-pamlinux-pam : linux-pamlinux-pam : linux-pamlinux-pam : linux-pamlinux-pam : linux-pamlinux-pam : linux-pamlinux-pam : linux-pamlinux-pam : linux-pamlinux-pam : linux-pamlinux-pam : linux-pamlinux-pam : linux-pamlinux-pam : linux-pamlinux-pam : linux-pamlinux-pam : linux-pamlinux-pam : linux-pamlinux-pam : linux-pamlinux-pam : linux-pam

AI-Powered Remediation

Generate remediation guidance or a C-suite brief for this vulnerability.

Executive Intelligence Brief