« List of all CVEs

CVE-2001-1147

Published: 6/25/2002 Last updated: 8/8/2024 Reserved: 3/15/2002

The PAM implementation in /bin/login of the util-linux package before 2.11 causes a password entry to be rewritten across multiple PAM calls, which could provide the credentials of one user to a different user, when used in certain PAM modules such as pam_limits.

CNA assigner: mitre (8254265b-2729-46b6-b9e3-3dfca2d5bfca) Requested by: n/a

Opam packages affected (1)

vhdlib

Products affected (1)

Product Vendor Version
n/a n/a n/a

References (14)