« List of all CVEs

CVE-2011-3149

Published: 7/22/2012 Last updated: 8/6/2024 Reserved: 8/16/2011

The _expand_arg function in the pam_env module (modules/pam_env/pam_env.c) in Linux-PAM (aka pam) before 1.1.5 does not properly handle when environment variable expansion can overflow, which allows local users to cause a denial of service (CPU consumption).

CNA assigner: mitre (8254265b-2729-46b6-b9e3-3dfca2d5bfca) Requested by: n/a

Opam packages affected (2)

conf-pam pam

Products affected (0)

No product listed.

References (24)