« List of all CVEs

CVE-2020-27780

Published: 12/17/2020 Last updated: 8/4/2024 Reserved: 10/27/2020

A flaw was found in Linux-Pam in versions prior to 1.5.1 in the way it handle empty passwords for non-existing users. When the user doesn't exist PAM try to authenticate with root and in the case of an empty password it successfully authenticate.

CNA assigner: redhat (53f830b8-0a3f-465b-8143-3b8a9948e749) Requested by: n/a

Opam packages affected (2)

conf-pam pam

Products affected (1)

Product Vendor Version
pam n/a n/a

References (2)