CVE-2015-3238

The _unix_run_helper_binary function in the pam_unix module in Linux-PAM (aka pam) before 1.2.1, when unable to directly access passwords, allows local users to enumerate usernames or cause a denial of service (hang) via a large password.
Configurations

Configuration 1 (hide)

cpe:2.3:a:linux-pam:linux-pam:*:*:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:a:oracle:sparc-opl_service_processor:*:*:*:*:*:*:*:*

History

12 Feb 2023, 23:15

Type Values Removed Values Added
References
  • {'url': 'https://access.redhat.com/security/cve/CVE-2015-3238', 'name': 'https://access.redhat.com/security/cve/CVE-2015-3238', 'tags': [], 'refsource': 'MISC'}
  • {'url': 'https://access.redhat.com/errata/RHSA-2015:1640', 'name': 'https://access.redhat.com/errata/RHSA-2015:1640', 'tags': [], 'refsource': 'MISC'}
Summary It was discovered that the _unix_run_helper_binary() function of PAM's unix_pam module could write to a blocking pipe, possibly causing the function to become unresponsive. An attacker able to supply large passwords to the unix_pam module could use this flaw to enumerate valid user accounts, or cause a denial of service on the system. The _unix_run_helper_binary function in the pam_unix module in Linux-PAM (aka pam) before 1.2.1, when unable to directly access passwords, allows local users to enumerate usernames or cause a denial of service (hang) via a large password.

02 Feb 2023, 15:16

Type Values Removed Values Added
Summary The _unix_run_helper_binary function in the pam_unix module in Linux-PAM (aka pam) before 1.2.1, when unable to directly access passwords, allows local users to enumerate usernames or cause a denial of service (hang) via a large password. It was discovered that the _unix_run_helper_binary() function of PAM's unix_pam module could write to a blocking pipe, possibly causing the function to become unresponsive. An attacker able to supply large passwords to the unix_pam module could use this flaw to enumerate valid user accounts, or cause a denial of service on the system.
References
  • (MISC) https://access.redhat.com/security/cve/CVE-2015-3238 -
  • (MISC) https://access.redhat.com/errata/RHSA-2015:1640 -

Information

Published : 2015-08-24 14:59

Updated : 2023-12-10 11:46


NVD link : CVE-2015-3238

Mitre link : CVE-2015-3238

CVE.ORG link : CVE-2015-3238


JSON object : View

Products Affected

oracle

  • sparc-opl_service_processor

linux-pam

  • linux-pam
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor