CVE-2024-22365

linux-pam (aka Linux PAM) before 1.6.0 allows attackers to cause a denial of service (blocked login process) via mkfifo because the openat call (for protect_dir) lacks O_DIRECTORY.
Configurations

Configuration 1 (hide)

cpe:2.3:a:linux-pam:linux-pam:*:*:*:*:*:*:*:*

History

14 Feb 2024, 00:27

Type Values Removed Values Added
CPE cpe:2.3:a:linux-pam:linux-pam:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.5
First Time Linux-pam
Linux-pam linux-pam
CWE NVD-CWE-noinfo
References () http://www.openwall.com/lists/oss-security/2024/01/18/3 - () http://www.openwall.com/lists/oss-security/2024/01/18/3 - Exploit, Mailing List, Patch, Release Notes
References () https://github.com/linux-pam/linux-pam - () https://github.com/linux-pam/linux-pam - Product
References () https://github.com/linux-pam/linux-pam/commit/031bb5a5d0d950253b68138b498dc93be69a64cb - () https://github.com/linux-pam/linux-pam/commit/031bb5a5d0d950253b68138b498dc93be69a64cb - Patch
References () https://github.com/linux-pam/linux-pam/releases/tag/v1.6.0 - () https://github.com/linux-pam/linux-pam/releases/tag/v1.6.0 - Release Notes

06 Feb 2024, 13:53

Type Values Removed Values Added
Summary
  • (es) linux-pam (también conocido como Linux PAM) anterior a 1.6.0 permite a los atacantes provocar una denegación de servicio (proceso de inicio de sesión bloqueado) a través de mkfifo porque la llamada openat (para protect_dir) carece de O_DIRECTORY.

06 Feb 2024, 08:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-02-06 08:15

Updated : 2024-02-14 00:27


NVD link : CVE-2024-22365

Mitre link : CVE-2024-22365

CVE.ORG link : CVE-2024-22365


JSON object : View

Products Affected

linux-pam

  • linux-pam