« List of all CVEs

CVE-2011-3148

Published: 7/22/2012 Last updated: 8/6/2024 Reserved: 8/16/2011

Stack-based buffer overflow in the _assemble_line function in modules/pam_env/pam_env.c in Linux-PAM (aka pam) before 1.1.5 allows local users to cause a denial of service (crash) and possibly execute arbitrary code via a long string of white spaces at the beginning of the ~/.pam_environment file.

CNA assigner: mitre (8254265b-2729-46b6-b9e3-3dfca2d5bfca) Requested by: n/a

Opam packages affected (2)

conf-pam pam

Products affected (1)

Product Vendor Version
n/a n/a V500R005C00

References (12)